Vulnerability Intelligence Report
CVE-2020-36518
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:4.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787 Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| fasterxml | jackson-databind | all |
| oracle | big_data_spatial_and_graph | all |
| oracle | coherence | 14.1.1.0.0 |
| oracle | commerce_platform | 11.3.0, 11.3.1, 11.3.2 |
| oracle | communications_billing_and_revenue_management | all |
| oracle | communications_cloud_native_core_binding_support_function | 22.1.3 |
| oracle | communications_cloud_native_core_console | 1.9.0 |
| oracle | communications_cloud_native_core_network_repository_function | 22.1.2, 22.2.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | 22.1.0, 22.1.1 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.1 |
| oracle | communications_cloud_native_core_service_communication_proxy | 22.2.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 22.2.0 |
| oracle | financial_services_analytical_applications_infrastructure | 8.1.1.0, 8.1.2.0, 8.1.2.1 |
| oracle | financial_services_behavior_detection_platform | 8.0.7.0.0, 8.0.8 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0, 8.0.8.3.0 |
| oracle | financial_services_enterprise_case_management | 8.0.7.1, 8.0.7.2, 8.0.8.0, 8.0.8.1 |
| oracle | financial_services_trade-based_anti_money_laundering | 8.0.7, 8.0.8 |
| oracle | global_lifecycle_management_nextgen_oui_framework | 13.9.4.2.2 |
| oracle | global_lifecycle_management_opatch | all |
| oracle | graph_server_and_client | all |
| oracle | health_sciences_empirica_signal | 9.1.0.5.2 |
| oracle | peoplesoft_enterprise_peopletools | 8.58, 8.59 |
| oracle | primavera_gateway | all |
| oracle | primavera_p6_enterprise_project_portfolio_management | all |
| oracle | primavera_unifier | 18.0, 19.12, 20.12, 21.12 |
| oracle | retail_sales_audit | 15.0.3.1 |
| oracle | sd-wan_edge | 9.0, 9.1 |
| oracle | spatial_studio | all |
| oracle | utilities_framework | 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.5.0 |
| oracle | weblogic_server | 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
| debian | debian_linux | 9.0, 10.0, 11.0 |
| netapp | active_iq_unified_manager | all |
| netapp | cloud_insights_acquisition_unit | all |
| netapp | oncommand_insight | all |
| netapp | oncommand_workflow_automation | all |
| netapp | snap_creator_framework | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.860%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-03-11T00:00:00 |
| Published | 2022-03-11T00:00:00 |
| Last Updated | 2025-08-27T20:34:32 |
Community Chatter & Buzz