VDB
BDU%3A2019-02897
BDU%3A2019-02897
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции FasterXML Java-библиотеки для грамматического разбора JSON файлов jackson-databind, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Oracle Corp., FasterXML, LLC | Red Hat Enterprise Linux, Debian GNU/Linux, Business Process Management Suite, JD Edwards EnterpriseOne Tools, Primavera Unifier, Primavera P6 Enterprise Project Portfolio Management, WebCenter Portal, Retail Xstore Point of Service, Jackson-databind, OpenShift Container Platform, Communications Billing and Revenue Management, Retail Workforce Management Software, Jboss BRMS, Communications Unified, Primavera Gateway, Enterprise Manager for Virtualization, Retail Customer Management and Segmentation Foundation, Insurance Performance Insight, Insurance Allocation Manager for Enterprise Profitability, Financial Services Retail Customer Analytics, Financial Services Profitability Management, Financial Services Price Creation and Discovery, Financial Services Institutional Performance Analytics, Financial Services Funds Transfer Pricing, Financial Services Analytical Applications Infrastructure, Banking Platform, Jboss Fuse, JBoss A-MQ, OpenShift Application Runtimes, Automation Manager |
Timeline
- Aug 16, 2019 CVE Published
- Mar 23, 2021 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
References
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html url
- https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b url
- https://github.com/FasterXML/jackson-databind/issues/2186 url
- https://nvd.nist.gov/vuln/detail/CVE-2018-19361 url
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html url
- https://www.debian.org/security/2019/dsa-4452 url
- https://access.redhat.com/security/cve/cve-2018-19361 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1666484 url
- https://www.cvedetails.com/cve/CVE-2018-19361/?q=CVE-2018-19361 url