VDB
BDU%3A2019-04782
BDU%3A2019-04782
PUBLISHED
CVSS 10 CRITICAL
Уязвимость реализации механизма полиморфной типизации данных библиотеки jackson-databind, позволяющая нарушителю выполнить вредоносную нагрузку
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Oracle Corp., Red Hat Inc., Fedora Project, FasterXML, LLC, Apache Software Foundation, АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Debian GNU/Linux, JD Edwards EnterpriseOne Tools, WebCenter Portal, Oracle Retail Customer Management and Segmentation Foundation, Red Hat Enterprise Linux, Red Hat JBoss Fuse, Fedora, Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, JBoss Enterprise Application Platform, Jackson-databind, JBoss Data Grid, OpenShift Application Runtimes, Red Hat Process Automation Manager, Drill, Red Hat Single Sign-On, OpenShift Container Platform, Red Hat Descision Manager, JD Edwards EnterpriseOne Orchestrator, JBoss A-MQ Streaming, Siebel UI Framework, Communications Billing and Revenue Management, Oracle Retail Merchandising System, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, Oracle Global Lifecycle Management OPatch, РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Dec 22, 2019 CVE Published
- Mar 5, 2025 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
References
- https://www.oracle.com/security-alerts/cpujan2020.html advisory
- https://github.com/FasterXML/jackson-databind/issues/2478 url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd@%3Ccommits.iceberg.apache.org%3E url
- https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E url
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/ url
- https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 url
- https://seclists.org/bugtraq/2019/Oct/6 url
- https://security.netapp.com/advisory/ntap-20191017-0006/ url
- https://www.debian.org/security/2019/dsa-4542 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url
- https://access.redhat.com/security/cve/CVE-2019-16943 advisory