← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-36182

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:5.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-502 ↗CWE-502 Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
fasterxml jackson-databind all
netapp cloud_backup all
netapp service_level_manager all
debian debian_linux 9.0
oracle agile_plm 9.3.6
oracle application_testing_suite 13.3.0.1
oracle autovue_for_agile_product_lifecycle_management 21.0.2
oracle banking_corporate_lending_process_management 14.2, 14.3, 14.5
oracle banking_credit_facilities_process_management 14.2, 14.3, 14.5
oracle banking_extensibility_workbench 14.2, 14.3, 14.5
oracle banking_supply_chain_finance 14.2, 14.3, 14.5
oracle banking_treasury_management 4.4
oracle banking_virtual_account_management 14.2.0, 14.3.0, 14.5.0
oracle blockchain_platform all
oracle commerce_platform 11.2.0
oracle communications_billing_and_revenue_management 7.5.0.23.0, 12.0.0.3.0
oracle communications_cloud_native_core_policy 1.14.0
oracle communications_cloud_native_core_unified_data_repository 1.4.0
oracle communications_convergent_charging_controller 12.0.4.0.0
oracle communications_diameter_signaling_route all
oracle communications_element_manager all
oracle communications_evolved_communications_application_server 7.1
oracle communications_instant_messaging_server 10.0.1.5.0
oracle communications_network_charging_and_control 12.0.4.0.0
oracle communications_offline_mediation_controller 12.0.0.3
oracle communications_policy_management 12.5.0
oracle communications_pricing_design_center 12.0.0.4.0
oracle communications_services_gatekeeper 7.0
oracle communications_session_report_manager all
oracle communications_session_route_manager all
oracle communications_unified_inventory_management 7.4.1
oracle data_integrator 12.2.1.4.0
oracle documaker 12.6.0, 12.6.3, 12.6.4
oracle goldengate_application_adapters 19.1.0.0.0
oracle insurance_policy_administration 11.0.2
oracle insurance_rules_palette 11.0.2
oracle jd_edwards_enterpriseone_orchestrator all
oracle jd_edwards_enterpriseone_tools all
oracle primavera_gateway 20.12.0
oracle primavera_unifier 17.2, 18.8, 19.12, 20.12
oracle retail_customer_management_and_segmentation_foundation all
oracle retail_merchandising_system 15.0.3
oracle retail_service_backbone 14.1.3.2, 15.0.3.1, 16.0.3.0
oracle retail_xstore_point_of_service 16.0.6, 17.0.4, 18.0.3, 19.0.2
oracle webcenter_portal 12.2.1.3.0, 12.2.1.4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.018%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-01-06T00:00:00
Published2021-01-06T22:30:22
Last Updated2024-08-04T17:23:09

LINK COPIED TO CLIPBOARD