Lucene search

K
cve[email protected]CVE-2018-11307
HistoryJul 09, 2019 - 4:15 p.m.

CVE-2018-11307

2019-07-0916:15:12
CWE-502
web.nvd.nist.gov
143
cve
2018
11307
fasterxml
jackson-databind
nvd
security
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

Affected configurations

NVD
Node
fasterxmljackson-databindRange2.0.02.6.7.3
OR
fasterxmljackson-databindRange2.7.02.7.9.4
OR
fasterxmljackson-databindRange2.8.02.8.11.2
OR
fasterxmljackson-databindRange2.9.02.9.6
Node
redhatopenshift_container_platformMatch3.11
Node
redhatenterprise_linuxMatch7.0
AND
redhatopenshift_container_platformMatch4.1
Node
oracleclusterwareMatch12.1.0.2.0
OR
oraclecommunications_instant_messaging_serverMatch10.0.1.2.0
OR
oracleglobal_lifecycle_management_opatchRange<11.2.0.3.23
OR
oracleglobal_lifecycle_management_opatchRange12.2.0.1.012.2.0.1.19
OR
oracleglobal_lifecycle_management_opatchRange13.9.4.0.013.9.4.2.1
OR
oracleretail_customer_management_and_segmentation_foundationMatch17.0
OR
oracleutilities_advanced_spatial_and_operational_analyticsMatch2.7.0.1

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%