VDB
BDU%3A2020-04468
BDU%3A2020-04468
PUBLISHED
CVSS 10 CRITICAL
Уязвимость компонента spring-aop библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., ООО «РусБИТех-Астра», Red Hat Inc., Сообщество свободного программного обеспечения, FasterXML, LLC, ООО «Ред Софт», АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Primavera Unifier, WebCenter Portal, WebLogic Server, Oracle Retail Merchandising System, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, Database Server, Debian GNU/Linux, Jboss Fuse, Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, OpenShift Application Runtimes, JBoss Enterprise Application Platform Continuous Delivery, Enterprise Manager Base Platform, Red Hat Descision Manager, Oracle Agile PLM, Communications Instant Messaging Server, Siebel UI Framework, Jackson-databind, Oracle Communications Contacts Server, Oracle Communications Evolved Communications Application Server, Communications Network Charging and Control, JD Edwards EnterpriseOne Orchestrator, JD Edwards EnterpriseOne Tools, Communications Billing and Revenue Management, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, GoldenGate Stream Analytics, Oracle Global Lifecycle Management OPatch, Red Hat Satellite, Communications Diameter Signaling Router, Communications Calendar Server, JBoss Data Grid, Banking Platform, РЕД ОС (запись в едином реестре российских программ №3751), РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Sep 29, 2020 CVE Published
- Jul 11, 2025 CVE Updated
References
- https://github.com/FasterXML/jackson-databind/issues/2680 url
- https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://access.redhat.com/security/cve/cve-2020-11619 url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url