Vulnerability Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Databind | >= 2.0.0, < 2.8.11.5 |
| Netapp | Active Iq Unified Manager | >= 7.3 |
| Netapp | Oncommand Api Services | - |
| Netapp | Oncommand Workflow Automation | - |
| Netapp | Service Level Manager | - |
| Netapp | Steelstore Cloud Integrated Storage | - |
| Debian | Debian Linux | 8.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2 |
| Redhat | Enterprise Linux | 6.0 |
| Oracle | Customer Management And Segmentation Foundation | < 18.0 |
| Oracle | Goldengate Application Adapters | 19.1.0.0.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 17.0 |
| Oracle | Weblogic Server | 12.2.1.3.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2019:3200Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0159Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445Third Party Advisory
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3..PatchThird Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2460Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d28
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab
- https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7d
- https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741
FAQ
What is CVE-2019-17267?
CVE-2019-17267 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
How severe is CVE-2019-17267?
CVE-2019-17267 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17267?
Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Netapp Active Iq Unified Manager, Netapp Oncommand Api Services, Netapp Oncommand Workflow Automation, Netapp Service Level Manager.