Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28941
HistoryJan 08, 2021 - 7:27 a.m.

Arbitrary Code Execution

2021-01-0807:27:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
jackson-databind
rce
vulnerability
deserialization
org.apache.tomcat.dbcp.dbcp.cpdsadapter.driveradaptercpd

EPSS

0.003

Percentile

66.0%

jackson-databind is vulnerable to remote code execution (RCE). The vulnerability exists through the lack of sanitization of the org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPD class through deserialization.