VDB
CISA-2020-11113
CISA-2020-11113
PUBLISHED
CVSS 8.8 HIGH
Reported by mitre · Published March 31, 2020
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| oracle | financial_services_institutional_performance_analytics | 8.0.7, 8.0.7, 8.1.0 |
| oracle | financial_services_retail_customer_analytics | 8.0.6, 8.0.6 |
| oracle | retail_sales_audit | 14.1, 14.1 |
| oracle | retail_merchandising_system | 15.0, 15.0 |
| oracle | banking_digital_experience | 19.1, 20.1, 19.1 |
| oracle | weblogic_server | 12.2.1.3.0, 12.2.1.3.0 |
| netapp | steelstore_cloud_integrated_storage | *, * |
| oracle | communications_element_manager | 8.2.0, 8.2.0 |
| oracle | primavera_unifier | 18.8, 17.7, 19.12 |
| oracle | communications_evolved_communications_application_server | 7.1, 7.1 |
| oracle | retail_xstore_point_of_service | 15.0, 15.0 |
| oracle | communications_diameter_signaling_router | 8.0.0, 8.0.0 |
| oracle | communications_instant_messaging_server | 10.0.1.4.0, 10.0.1.4.0 |
| oracle | insurance_policy_administration_j2ee | 11.0.2.25, 11.0.2.25 |
| oracle | autovue_for_agile_product_lifecycle_management | 21.0.2, 21.0.2 |
| n/a | n/a | *, n/a |
| oracle | enterprise_manager_base_platform | 13.3.0.0, 13.3.0.0 |
| oracle | jd_edwards_enterpriseone_orchestrator | 0, 0 |
| oracle | communications_session_route_manager | 8.2.0, 8.2.0 |
…and 9 more
Timeline
- Mar 31, 2020 CVE Published
- Aug 27, 2025 CVE Updated
References
- [debian-lts-announce] 20200417 [SECURITY] [DLA 2179-1] jackson-databind security update mailing-listx_refsource_MLIST
- x_refsource_MISC
- x_refsource_MISC
- x_refsource_CONFIRM
- x_refsource_MISC
- x_refsource_MISC
- x_refsource_MISC
- x_refsource_MISC