← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:4.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
fasterxml jackson-databind all
debian debian_linux 8.0, 9.0, 10.0
fedoraproject fedora 30, 31
redhat jboss_enterprise_application_platform 7.2, 7.3
redhat enterprise_linux_server 6.0, 7.0, 8.0
oracle banking_platform 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.9.0
oracle communications_billing_and_revenue_management 7.5.0.23.0, 12.0.0.3.0
oracle communications_calendar_server 8.0.0.2.0, 8.0.0.3.0
oracle communications_cloud_native_core_network_slice_selection_function 1.2.1
oracle communications_evolved_communications_application_server 7.1
oracle global_lifecycle_management_nextgen_oui_framework 12.2.1.3.0, 12.2.1.4.0, 13.9.4.2.2
oracle goldengate_application_adapters 19.1.0.0.0
oracle jd_edwards_enterpriseone_orchestrator 9.2
oracle jd_edwards_enterpriseone_tools 9.2
oracle primavera_gateway 16.1, 16.2, 19.12.0
oracle retail_merchandising_system 15.0.3, 16.0.2, 16.0.3
oracle retail_sales_audit 14.1
oracle siebel_engineering_-_installer_\&_deployment all
oracle trace_file_analyzer 12.2.0.1, 18c, 19c
oracle webcenter_portal 12.2.1.3.0, 12.2.1.4.0
oracle webcenter_sites 12.2.1.3.0, 12.2.1.4.0
oracle weblogic_server 12.2.1.3.0, 12.2.1.4.0
netapp active_iq_unified_manager all
netapp oncommand_api_services all
netapp oncommand_workflow_automation all
netapp service_level_manager all
netapp steelstore_cloud_integrated_storage all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.861%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-09-29T00:00:00
Published2019-10-01T16:06:23
Last Updated2024-08-05T01:24:48

LINK COPIED TO CLIPBOARD