VDB

BDU%3A2019-04778

BDU%3A2019-04778 PUBLISHED CVSS 7.5 HIGH

Уязвимость реализации механизма полиморфной типизации данных библиотеки jackson-databind, позволяющая нарушителю выполнить вредоносную нагрузку

Risk Scores

CVSS 2.0
7.5

Affected Products

VendorProductVersions
Сообщество свободного программного обеспечения, Oracle Corp., Red Hat Inc., Fedora Project, FasterXML, LLC, Apache Software Foundation, АО «Концерн ВНИИНС»Debian GNU/Linux, JD Edwards EnterpriseOne Tools, Oracle Retail Customer Management and Segmentation Foundation, Red Hat Enterprise Linux, Fedora, Jboss Fuse, Jboss BRMS, Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, OpenShift Application Runtimes, JBoss Enterprise Application Platform, Jackson-databind, JBoss Data Grid, Red Hat Single Sign-On, Red Hat Process Automation Manager, JBoss Enterprise Application Platform Continuous Delivery, Drill, OpenShift Container Platform, Red Hat Descision Manager, JD Edwards EnterpriseOne Orchestrator, JBoss A-MQ Streaming, Geode, Siebel UI Framework, Communications Billing and Revenue Management, Oracle Retail Merchandising System, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177)

Timeline

  • Dec 22, 2019 CVE Published
  • Nov 21, 2023 CVE Updated
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›