← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:4.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-787 ↗CWE-787 Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
fasterxml jackson-databind all
oracle big_data_spatial_and_graph all
oracle coherence 14.1.1.0.0
oracle commerce_platform 11.3.0, 11.3.1, 11.3.2
oracle communications_billing_and_revenue_management all
oracle communications_cloud_native_core_binding_support_function 22.1.3
oracle communications_cloud_native_core_console 1.9.0
oracle communications_cloud_native_core_network_repository_function 22.1.2, 22.2.0
oracle communications_cloud_native_core_network_slice_selection_function 22.1.0, 22.1.1
oracle communications_cloud_native_core_security_edge_protection_proxy 22.1.1
oracle communications_cloud_native_core_service_communication_proxy 22.2.0
oracle communications_cloud_native_core_unified_data_repository 22.2.0
oracle financial_services_analytical_applications_infrastructure 8.1.1.0, 8.1.2.0, 8.1.2.1
oracle financial_services_behavior_detection_platform 8.0.7.0.0, 8.0.8
oracle financial_services_crime_and_compliance_management_studio 8.0.8.2.0, 8.0.8.3.0
oracle financial_services_enterprise_case_management 8.0.7.1, 8.0.7.2, 8.0.8.0, 8.0.8.1
oracle financial_services_trade-based_anti_money_laundering 8.0.7, 8.0.8
oracle global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2
oracle global_lifecycle_management_opatch all
oracle graph_server_and_client all
oracle health_sciences_empirica_signal 9.1.0.5.2
oracle peoplesoft_enterprise_peopletools 8.58, 8.59
oracle primavera_gateway all
oracle primavera_p6_enterprise_project_portfolio_management all
oracle primavera_unifier 18.0, 19.12, 20.12, 21.12
oracle retail_sales_audit 15.0.3.1
oracle sd-wan_edge 9.0, 9.1
oracle spatial_studio all
oracle utilities_framework 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.5.0
oracle weblogic_server 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
debian debian_linux 9.0, 10.0, 11.0
netapp active_iq_unified_manager all
netapp cloud_insights_acquisition_unit all
netapp oncommand_insight all
netapp oncommand_workflow_automation all
netapp snap_creator_framework all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.860%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-03-11T00:00:00
Published2022-03-11T00:00:00
Last Updated2025-08-27T20:34:32

LINK COPIED TO CLIPBOARD