HIGH · 8.1

CVE-2020-24616

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

Vulnerability Description

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FasterxmlJackson-Databind>= 2.0.0, < 2.9.10.6
NetappActive Iq Unified Manager-
OracleAgile Plm9.3.6
OracleApplication Testing Suite13.3.0.1
OracleAutovue For Agile Product Lifecycle Management21.0.2
OracleBanking Liquidity Management14.2
OracleBanking Supply Chain Finance14.2
OracleBlockchain Platform< 21.1.2
OracleCommunications Calendar Server8.0
OracleCommunications Cloud Native Core Unified Data Repository1.4.0
OracleCommunications Contacts Server8.0
OracleCommunications Diameter Signaling Router>= 8.0.0, <= 8.2.2
OracleCommunications Element Manager>= 8.2.0, <= 8.2.4.0
OracleCommunications Evolved Communications Application Server7.1
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleCommunications Messaging Server8.1
OracleCommunications Offline Mediation Controller12.0.0.3
OracleCommunications Policy Management12.5.0
OracleCommunications Pricing Design Center12.0.0.4.0
OracleCommunications Services Gatekeeper7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24616?

CVE-2020-24616 is a vulnerability with a CVSS score of 8.1 (HIGH). FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

How severe is CVE-2020-24616?

CVE-2020-24616 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24616?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Netapp Active Iq Unified Manager, Oracle Agile Plm, Oracle Application Testing Suite, Oracle Autovue For Agile Product Lifecycle Management.