VDB

BDU%3A2022-03804

BDU%3A2022-03804 PUBLISHED CVSS 9.300000190734863 CRITICAL

Уязвимость компонента org.apache.commons.dbcp2.datasources.PerUserPoolDataSource библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю выполнить произвольный код

Risk Scores

CVSS 2.0
9.300000190734863

Affected Products

VendorProductVersions
Сообщество свободного программного обеспечения, Oracle Corp., FasterXML, LLC, NetApp Inc., АО "НППКТ", АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС»Debian GNU/Linux, WebCenter Portal, Application Testing Suite, Banking Platform, Insurance Policy Administration J2EE, Blockchain Platform, Jackson-databind, Service Level Manager (SLM), Autovue for Agile Product Lifecycle Management, Banking Treasury Management, Banking Virtual Account Management, Communications Cloud Native Core Policy, Communications Diameter Signaling Router, Communications Instant Messaging Server, Communications Interactive Session Recorder, Communications Online Mediation Controller, Communications Pricing Design Center, Communications Services Gatekeeper, Communications Unified Inventory Management, Oracle Documaker, Retail Merchandising System (RMS), Xstore Point-of-Service, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ROSA Virtualization (запись в едином реестре российских программ №5091), РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177)

Timeline

  • Jun 27, 2022 CVE Published
  • Mar 5, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›