Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25680
HistoryJun 15, 2020 - 5:05 a.m.

Remote Code Execution (RCE)

2020-06-1505:05:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.034 Low

EPSS

Percentile

91.5%

jackson-databind is vulnerable to deserialization of untrusted data that can lead to remote code execution. It is possible because it does not filter the untrusted serialization classes weblogic/oracle-aqjms from interaction between serialization gadgets and typing by default.