VDB
BDU%3A2022-03804
BDU%3A2022-03804
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость компонента org.apache.commons.dbcp2.datasources.PerUserPoolDataSource библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Oracle Corp., FasterXML, LLC, NetApp Inc., АО "НППКТ", АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Debian GNU/Linux, WebCenter Portal, Application Testing Suite, Banking Platform, Insurance Policy Administration J2EE, Blockchain Platform, Jackson-databind, Service Level Manager (SLM), Autovue for Agile Product Lifecycle Management, Banking Treasury Management, Banking Virtual Account Management, Communications Cloud Native Core Policy, Communications Diameter Signaling Router, Communications Instant Messaging Server, Communications Interactive Session Recorder, Communications Online Mediation Controller, Communications Pricing Design Center, Communications Services Gatekeeper, Communications Unified Inventory Management, Oracle Documaker, Retail Merchandising System (RMS), Xstore Point-of-Service, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ROSA Virtualization (запись в едином реестре российских программ №5091), РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Jun 27, 2022 CVE Published
- Mar 5, 2025 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35490 url
- https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 url
- https://github.com/FasterXML/jackson-databind/issues/2986 url
- https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html url
- https://security.netapp.com/advisory/ntap-20210122-0005/ url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://www.oracle.com/security-alerts/cpujan2022.html url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.1/ url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2024-2420 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url