← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-19361

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:10.60%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
fasterxml jackson-databind all
debian debian_linux 8.0, 9.0
oracle business_process_management_suite 12.1.3.0.0, 12.2.1.3.0
oracle primavera_p6_enterprise_project_portfolio_management 15.1, 15.2, 16.1, 16.2, 18.8
oracle primavera_unifier 16.1, 16.2, 18.8
oracle retail_workforce_management_software 1.60.9.0.0
oracle webcenter_portal 12.2.1.3.0
redhat automation_manager 7.3.1
redhat decision_manager 7.3.1
redhat jboss_bpm_suite 6.4.11
redhat jboss_brms 6.4.10
redhat openshift_container_platform 3.11

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
10.599%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-11-19T00:00:00
Published2019-01-02T18:00:00
Patch Date2018-11-19
Last Updated2024-08-05T11:37:11

LINK COPIED TO CLIPBOARD