Vulnerability Description
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Modules-Java8 | < 2.9.8 |
| Oracle | Clusterware | 12.1.0.2.0 |
| Oracle | Database Server | 12.1.0.2 |
| Oracle | Global Lifecycle Management Opatch | < 11.2.0.3.23 |
| Oracle | Nosql Database | < 19.3.12 |
| Netapp | Active Iq Unified Manager | >= 7.3 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1665601Issue TrackingThird Party Advisory
- https://github.com/FasterXML/jackson-modules-java8/issues/90ExploitPatchThird Party Advisory
- https://github.com/FasterXML/jackson-modules-java8/pull/87PatchThird Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d28
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd9
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b
- https://security.netapp.com/advisory/ntap-20200904-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1665601Issue TrackingThird Party Advisory
FAQ
What is CVE-2018-1000873?
CVE-2018-1000873 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be...
How severe is CVE-2018-1000873?
CVE-2018-1000873 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000873?
Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Modules-Java8, Oracle Clusterware, Oracle Database Server, Oracle Global Lifecycle Management Opatch, Oracle Nosql Database.