VDB
BDU%3A2021-00767
BDU%3A2021-00767
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость класса ignite-jta библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., FasterXML, LLC, АО "НППКТ" | Primavera Unifier, WebLogic Server, Oracle Retail Merchandising System, Retail Xstore Point of Service, Enterprise Manager Base Platform, Financial Services Price Creation and Discovery, Oracle Agile PLM, Oracle Retail Service Backbone, Financial Services Analytical Applications Infrastructure, Oracle Banking Platform, Communications Instant Messaging Server, Jackson-databind, Oracle Communications Contacts Server, Oracle Communications Evolved Communications Application Server, Communications Network Charging and Control, Oracle Retail Sales Audit, Oracle Global Lifecycle Management OPatch, Communications Diameter Signaling Router, Oracle Communications Element Manager, Oracle Communications Session Report Manager, Oracle Communications Session Route Manager, Financial Services Institutional Performance Analytics, Financial Services Retail Customer Analytics, Insurance Policy Administration J2EE, JD Edwards EnterpriseOne Orchestrator, JD Edwards EnterpriseOne Tools, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) |
Timeline
- Feb 16, 2021 CVE Published
- Sep 13, 2023 CVE Updated
References
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://github.com/FasterXML/jackson-databind/issues/2658 url
- https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.8/ url
- https://www.oracle.com/security-alerts/cpujul2020.html advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html advisory