VDB
BDU%3A2019-02899
BDU%3A2019-02899
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции FasterXML Java-библиотеки для грамматического разбора JSON файлов jackson-databind, позволяющая нарушителю получить доступ к конфиденциальным данным
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Oracle Corp., Fedora Project, Novell Inc., ООО «РусБИТех-Астра», Red Hat Inc., FasterXML, LLC, ООО «Ред Софт» | Debian GNU/Linux, JD Edwards EnterpriseOne Tools, Primavera Unifier, WebCenter Portal, Fedora, OpenSUSE Leap, Oracle Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, Red Hat JBoss Fuse, Jackson-databind, Communications Billing and Revenue Management, Communications Unified, Primavera Gateway, Enterprise Manager for Virtualization, Retail Customer Management and Segmentation Foundation, Insurance Performance Insight, Insurance Allocation Manager for Enterprise Profitability, Financial Services Retail Customer Analytics, Financial Services Profitability Management, Financial Services Price Creation and Discovery, Financial Services Institutional Performance Analytics, Financial Services Funds Transfer Pricing, Financial Services Analytical Applications Infrastructure, Banking Platform, OpenShift Application Runtimes, NoSQL Database, Communications Instant Messaging Server, Siebel UI Framework, Red Hat AMQ Streams, JBoss Enterprise Application Platform, Red Hat Single Sign-On, JD Edwards EnterpriseOne Orchestrator, Siebel Engineering - Installer & Deployment, JBoss EAP, GoldenGate Stream Analytics, РЕД ОС (запись в едином реестре российских программ №3751) |
Timeline
- Aug 16, 2019 CVE Published
- Sep 30, 2025 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
References
- http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/ url
- http://www.securityfocus.com/bid/109227 url
- https://access.redhat.com/errata/RHSA-2019:2858 url
- https://access.redhat.com/errata/RHSA-2019:2935 url
- https://access.redhat.com/errata/RHSA-2019:2936 url
- https://access.redhat.com/errata/RHSA-2019:2937 url
- https://access.redhat.com/errata/RHSA-2019:2938 url
- https://access.redhat.com/errata/RHSA-2019:2998 url
- https://access.redhat.com/errata/RHSA-2019:3044 url
- https://access.redhat.com/errata/RHSA-2019:3045 url
- https://access.redhat.com/errata/RHSA-2019:3046 url
- https://access.redhat.com/errata/RHSA-2019:3050 url
- https://access.redhat.com/errata/RHSA-2019:3149 url
- https://access.redhat.com/errata/RHSA-2019:3200 url
- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9 url
- https://github.com/FasterXML/jackson-databind/issues/2326 url
- https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2@%3Creviews.spark.apache.org%3E url
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E url
…and 18 more