Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21650
HistoryOct 08, 2019 - 2:07 a.m.

Remote Code Execution

2019-10-0802:07:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.012

Percentile

85.0%

FasterXML jackson-databind is vulnerable to deserialization of untrusted data. There is a polymorphic typing issue because there are more than one association gadget types related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

References