CRITICAL · 9.8

CVE-2019-17531

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON...

Vulnerability Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FasterxmlJackson-Databind>= 2.0.0, < 2.6.7.3
DebianDebian Linux8.0
RedhatJboss Enterprise Application Platform7.2
RedhatEnterprise Linux Server6.0
OracleBanking Platform2.4.0
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Calendar Server8.0.0.2.0
OracleCommunications Cloud Native Core Network Slice Selection Function1.2.1
OracleCommunications Evolved Communications Application Server7.1
OracleGlobal Lifecycle Management Nextgen Oui Framework12.2.1.3.0
OracleGoldengate Application Adapters19.1.0.0.0
OracleJd Edwards Enterpriseone Orchestrator9.2
OracleJd Edwards Enterpriseone Tools9.2
OraclePrimavera Gateway>= 17.7, <= 17.12.6
OracleRetail Merchandising System15.0.3
OracleRetail Sales Audit14.1
OracleSiebel Engineering - Installer \& Deployment<= 2.20.5
OracleTrace File Analyzer12.2.0.1
OracleWebcenter Portal12.2.1.3.0
OracleWebcenter Sites12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17531?

CVE-2019-17531 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON...

How severe is CVE-2019-17531?

CVE-2019-17531 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-17531?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Debian Debian Linux, Redhat Jboss Enterprise Application Platform, Redhat Enterprise Linux Server, Oracle Banking Platform.