CVE-2018-0125 PUBLISHED KEV CVSS 10 CRITICAL

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

EPSS 39.59% · 97.3th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
39.59%
97.3th percentile

Affected Products

VendorProductVersions
ciscorv134w_firmware1.0, 1.0, 1.0
FasterXMLjackson-databindbefore 2.9.1, before 2.8.10
n/aCisco RV132W and RV134WCisco RV132W and RV134W
ciscorv132w_firmware1.0, 1.0, 1.0

Timeline

References

…and 23 more

Open in Interactive Console →