VDB
BDU%3A2019-02896
BDU%3A2019-02896
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции FasterXML Java-библиотеки для грамматического разбора JSON файлов jackson-databind, позволяющая нарушителю оказать воздействие на целостность данных, получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Oracle Corp., FasterXML, LLC | Red Hat Enterprise Linux, Debian GNU/Linux, Business Process Management Suite, JD Edwards EnterpriseOne Tools, Primavera Unifier, Primavera P6 Enterprise Project Portfolio Management, WebCenter Portal, Retail Xstore Point of Service, Jackson-databind, OpenShift Container Platform, Communications Billing and Revenue Management, Retail Workforce Management Software, Jboss BRMS, Communications Unified, Primavera Gateway, Enterprise Manager for Virtualization, Retail Customer Management and Segmentation Foundation, Insurance Performance Insight, Insurance Allocation Manager for Enterprise Profitability, Financial Services Retail Customer Analytics, Financial Services Profitability Management, Financial Services Price Creation and Discovery, Financial Services Institutional Performance Analytics, Financial Services Funds Transfer Pricing, Financial Services Analytical Applications Infrastructure, Banking Platform, Jboss Fuse, JBoss A-MQ, OpenShift Application Runtimes, Automation Manager |
Timeline
- Aug 16, 2019 CVE Published
- Mar 23, 2021 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
References
- https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b url
- https://github.com/FasterXML/jackson-databind/issues/2186 url
- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8 url
- https://nvd.nist.gov/vuln/detail/CVE-2018-19360 url
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html url
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html url
- https://www.debian.org/security/2019/dsa-4452 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1666482 url
- https://access.redhat.com/security/cve/cve-2018-19360 url
- https://www.cvedetails.com/cve/CVE-2018-19360/?q=CVE-2018-19360 url