CRITICAL · 9.8

CVE-2017-7525

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciousl...

Vulnerability Description

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FasterxmlJackson-Databind< 2.6.7.1
DebianDebian Linux8.0
NetappOncommand Balance-
NetappOncommand Performance Manager-
NetappOncommand Shift-
NetappSnapcenter-
RedhatOpenshift Container Platform4.1
RedhatVirtualization4.0
RedhatVirtualization Host4.0
RedhatEnterprise Linux Server7.0
RedhatJboss Enterprise Application Platform6.0.0
OracleBanking Platform2.5.0
OracleCommunications Billing And Revenue Management7.5
OracleCommunications Communications Policy Management>= 12.0, <= 12.5.2
OracleCommunications Diameter Signaling Route< 8.3
OracleCommunications Instant Messaging Server10.0.1
OracleEnterprise Manager For Virtualization13.2.2
OracleFinancial Services Analytical Applications Infrastructure8.0.2.0.0
OracleGlobal Lifecycle Management Opatchauto< 12.2.0.1.14
OraclePrimavera Unifier>= 17.1, <= 17.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-7525?

CVE-2017-7525 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciousl...

How severe is CVE-2017-7525?

CVE-2017-7525 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-7525?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Debian Debian Linux, Netapp Oncommand Balance, Netapp Oncommand Performance Manager, Netapp Oncommand Shift.