HIGH · 7.5

CVE-2019-14439

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally ex...

Vulnerability Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
FasterxmlJackson-Databind>= 2.0.0, < 2.6.7.3
DebianDebian Linux8.0
FedoraprojectFedora29
ApacheDrill1.16.0
RedhatJboss Middleware Text-Only Advisories1.0
OracleBanking Platform2.4.0
OracleCommunications Diameter Signaling Router8.0.0
OracleCommunications Instant Messaging Server10.0.1.3.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.2, <= 8.0.8
OracleGlobal Lifecycle Management Opatch< 11.2.0.3.23
OracleGoldengate Stream Analytics< 19.1.0.0.1
OracleJd Edwards Enterpriseone Orchestrator9.2
OracleJd Edwards Enterpriseone Tools9.2
OraclePrimavera Gateway>= 17.7, <= 17.12
OracleRetail Customer Management And Segmentation Foundation17.0
OracleRetail Xstore Point Of Service7.1
OracleSiebel Engineering - Installer \& Deployment<= 19.8
OracleSiebel Ui Framework<= 19.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14439?

CVE-2019-14439 is a vulnerability with a CVSS score of 7.5 (HIGH). A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally ex...

How severe is CVE-2019-14439?

CVE-2019-14439 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14439?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Debian Debian Linux, Fedoraproject Fedora, Apache Drill, Redhat Jboss Middleware Text-Only Advisories.