VDB
BDU%3A2020-03616
BDU%3A2020-03616
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость компонента br.com.anteros.dbcp.AnterosDBCPConfig Java-библиотеки для грамматического разбора JSON файлов jackson-databind, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., ООО «РусБИТех-Астра», Red Hat Inc., Сообщество свободного программного обеспечения, FasterXML, LLC, ООО «Ред Софт», АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Primavera Unifier, WebCenter Portal, WebLogic Server, Oracle Retail Customer Management and Segmentation Foundation, Oracle Retail Merchandising System, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, Database Server, Debian GNU/Linux, Jboss Fuse, Retail Xstore Point of Service, OpenShift Application Runtimes, Red Hat Single Sign-On, Red Hat Process Automation Manager, JBoss Enterprise Application Platform Continuous Delivery, Enterprise Manager Base Platform, Red Hat Descision Manager, Oracle Agile PLM, Red Hat JBoss Data Grid, JBoss Enterprise Application Platform, JBoss EAP, Oracle Banking Platform, Communications Instant Messaging Server, Siebel UI Framework, Jackson-databind, Oracle Global Lifecycle Management OPatch, Oracle Communications Contacts Server, Oracle Communications Evolved Communications Application Server, Communications Network Charging and Control, JD Edwards EnterpriseOne Orchestrator, JD Edwards EnterpriseOne Tools, Communications Billing and Revenue Management, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, GoldenGate Stream Analytics, Communications Diameter Signaling Router, Communications Calendar Server, РЕД ОС (запись в едином реестре российских программ №3751), РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Jul 31, 2020 CVE Published
- Jul 1, 2025 CVE Updated
References
- https://github.com/FasterXML/jackson-databind/issues/2634 url
- https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E url
- https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html url
- https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-jackson-databind-cve-2020-9546-cve-2020-8840-cve-2020-9548-cve-2020-9547/?sphrase_id=1074012 url
- https://access.redhat.com/security/cve/cve-2020-9548 advisory