Lucene search

K
nvd[email protected]NVD:CVE-2018-12023
HistoryMar 21, 2019 - 4:00 p.m.

CVE-2018-12023

2019-03-2116:00:12
CWE-502
web.nvd.nist.gov
1

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.7%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

Affected configurations

NVD
Node
fasterxmljackson-databindRange2.7.02.7.9.4
OR
fasterxmljackson-databindRange2.8.02.8.11.2
OR
fasterxmljackson-databindRange2.9.02.9.6
Node
debiandebian_linuxMatch9.0
OR
fedoraprojectfedoraMatch29
Node
oraclejd_edwards_enterpriseone_toolsMatch9.2
OR
oracleretail_merchandising_systemMatch15.0
Node
redhatautomation_managerMatch7.3.1
OR
redhatdecision_managerMatch7.3.1
OR
redhatjboss_brmsMatch6.4.10
OR
redhatjboss_enterprise_application_platformMatch7.2.0
OR
redhatopenshift_container_platformMatch3.11
OR
redhatsingle_sign-onMatch7.3

References

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.7%