VDB
BDU%3A2020-04467
BDU%3A2020-04467
PUBLISHED
CVSS 10 CRITICAL
Уязвимость компонента commons-jelly библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., ООО «РусБИТех-Астра», Red Hat Inc., Сообщество свободного программного обеспечения, FasterXML, LLC, АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Primavera Unifier, WebCenter Portal, WebLogic Server, Oracle Retail Customer Management and Segmentation Foundation, Oracle Retail Merchandising System, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, Database Server, Debian GNU/Linux, Jboss Fuse, Retail Xstore Point of Service, OpenShift Application Runtimes, Red Hat Single Sign-On, JBoss Enterprise Application Platform Continuous Delivery, Enterprise Manager Base Platform, Red Hat Descision Manager, Oracle Agile PLM, Communications Instant Messaging Server, Siebel UI Framework, Jackson-databind, Oracle Communications Contacts Server, Oracle Communications Evolved Communications Application Server, Communications Network Charging and Control, JD Edwards EnterpriseOne Orchestrator, JD Edwards EnterpriseOne Tools, Communications Billing and Revenue Management, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, GoldenGate Stream Analytics, Red Hat Process Automation, Oracle Global Lifecycle Management OPatch, Communications Calendar Server, JBoss Data Grid, Banking Platform, РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Sep 29, 2020 CVE Published
- Mar 5, 2025 CVE Updated
References
- https://github.com/FasterXML/jackson-databind/issues/2682 url
- https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- https://access.redhat.com/security/cve/cve-2020-11620 url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url