VDB
CVE-2019-16943
CVE-2019-16943
PUBLISHED
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
EPSS 1.89% · 83.6th percentile
Risk Scores
EPSS Score
1.89%
83.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | access | |
| Ubuntu:18.04:LTS | jackson-databind | *, 0, 2.8.6-1 |
| Ubuntu:Pro:16.04:LTS | jackson-databind | 2.4.2-3, 0, 2.4.2-2 |
| Ubuntu:Pro:14.04:LTS | jackson-databind | 2.2.2-1ubuntu0.1~esm1, 2.2.2-1, 0 |
Exploit Intelligence
- https://www.cisa.gov/news-events/alerts/2024/09/18/cisa-adds-five-known-exploited-vulnerabilities-catalog (certbund)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
Timeline
- Oct 1, 2019 CVE Published
- Oct 12, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-16943 third-party-advisory
- https://github.com/FasterXML/jackson-databind/issues/2478 third-party-advisory
- https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 third-party-advisory
- https://ubuntu.com/security/notices/USN-4813-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16943 third-party-advisory
- Multiples vulnérabilités dans les produits Splunk advisory
- Multiples vulnérabilités dans les produits IBM advisory