VDB

CVE-2018-14721

CVE-2018-14721 PUBLISHED

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

EPSS 9.67% · 93.1th percentile

Risk Scores

EPSS Score
9.67%
93.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSjackson-databind0, 2.4.2-2, 2.4.2-3
Ubuntu:Pro:14.04:LTSjackson-databind0, 2.2.2-1, *

Timeline

  • Jan 2, 2019 CVE Published
  • Sep 27, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 19, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • Apr 2, 2025 EPSS Score
  • Apr 13, 2025 EPSS Score
  • Apr 15, 2025 EPSS Score
  • Apr 16, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›