CRITICAL · 9.8

CVE-2017-15095

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafte...

Vulnerability Description

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FasterxmlJackson-Databind>= 2.0.0, < 2.6.7.2
DebianDebian Linux8.0
RedhatOpenshift Container Platform3.11
RedhatSatellite6.4
RedhatSatellite Capsule6.4
RedhatEnterprise Linux7.0
RedhatJboss Enterprise Application Platform6.0.0
NetappOncommand Balance-
NetappOncommand Performance Manager-
NetappOncommand Shift-
NetappSnapcenter-
OracleBanking Platform2.5.0
OracleClusterware12.1.0.2.0
OracleCommunications Billing And Revenue Management7.5
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Instant Messaging Server10.0.1.2.0
OracleDatabase Server12.2.0.1
OracleEnterprise Manager For Virtualization13.2.2
OracleFinancial Services Analytical Applications Infrastructure8.0.2
OracleGlobal Lifecycle Management Opatchauto< 12.2.0.1.14

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-15095?

CVE-2017-15095 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafte...

How severe is CVE-2017-15095?

CVE-2017-15095 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-15095?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Debian Debian Linux, Redhat Openshift Container Platform, Redhat Satellite, Redhat Satellite Capsule.