← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-17531

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:5.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
fasterxml jackson-databind all
debian debian_linux 8.0
redhat jboss_enterprise_application_platform 7.2, 7.3
redhat enterprise_linux_server 6.0, 7.0, 8.0
oracle banking_platform 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.9.0
oracle communications_billing_and_revenue_management 7.5.0.23.0, 12.0.0.3.0
oracle communications_calendar_server 8.0.0.2.0, 8.0.0.3.0
oracle communications_cloud_native_core_network_slice_selection_function 1.2.1
oracle communications_evolved_communications_application_server 7.1
oracle global_lifecycle_management_nextgen_oui_framework 12.2.1.3.0, 12.2.1.4.0, 13.9.4.2.2
oracle goldengate_application_adapters 19.1.0.0.0
oracle jd_edwards_enterpriseone_orchestrator 9.2
oracle jd_edwards_enterpriseone_tools 9.2
oracle primavera_gateway 16.1, 16.2, 19.12.0
oracle retail_merchandising_system 15.0.3, 16.0.2, 16.0.3
oracle retail_sales_audit 14.1
oracle siebel_engineering_-_installer_\&_deployment all
oracle trace_file_analyzer 12.2.0.1, 18c, 19c
oracle webcenter_portal 12.2.1.3.0, 12.2.1.4.0
oracle webcenter_sites 12.2.1.3.0, 12.2.1.4.0
oracle weblogic_server 12.2.1.3.0, 12.2.1.4.0
netapp oncommand_workflow_automation all
netapp steelstore_cloud_integrated_storage all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.329%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-10-12T00:00:00
Published2019-10-12T20:07:34
Last Updated2024-08-05T01:40:16

LINK COPIED TO CLIPBOARD