VDB

BDU%3A2019-04782

BDU%3A2019-04782 PUBLISHED CVSS 10 CRITICAL

Уязвимость реализации механизма полиморфной типизации данных библиотеки jackson-databind, позволяющая нарушителю выполнить вредоносную нагрузку

Risk Scores

CVSS 2.0
10

Affected Products

VendorProductVersions
Сообщество свободного программного обеспечения, Oracle Corp., Red Hat Inc., Fedora Project, FasterXML, LLC, Apache Software Foundation, АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС»Debian GNU/Linux, JD Edwards EnterpriseOne Tools, WebCenter Portal, Oracle Retail Customer Management and Segmentation Foundation, Red Hat Enterprise Linux, Red Hat JBoss Fuse, Fedora, Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, JBoss Enterprise Application Platform, Jackson-databind, JBoss Data Grid, OpenShift Application Runtimes, Red Hat Process Automation Manager, Drill, Red Hat Single Sign-On, OpenShift Container Platform, Red Hat Descision Manager, JD Edwards EnterpriseOne Orchestrator, JBoss A-MQ Streaming, Siebel UI Framework, Communications Billing and Revenue Management, Oracle Retail Merchandising System, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, Oracle Global Lifecycle Management OPatch, РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177)

Timeline

  • Dec 22, 2019 CVE Published
  • Mar 5, 2025 CVE Updated
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›