HIGH · 7.5

CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Vulnerability Description

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
FasterxmlJackson-Databind< 2.12.6.1
OracleBig Data Spatial And Graph< 23.1
OracleCoherence14.1.1.0.0
OracleCommerce Platform11.3.0
OracleCommunications Billing And Revenue Management>= 12.0.0.4.0, <= 12.0.0.6.0
OracleCommunications Cloud Native Core Binding Support Function22.1.3
OracleCommunications Cloud Native Core Console1.9.0
OracleCommunications Cloud Native Core Network Repository Function22.1.2
OracleCommunications Cloud Native Core Network Slice Selection Function22.1.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy22.1.1
OracleCommunications Cloud Native Core Service Communication Proxy22.2.0
OracleCommunications Cloud Native Core Unified Data Repository22.2.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.7, <= 8.1.0.0
OracleFinancial Services Behavior Detection Platform>= 8.1.1.0, <= 8.1.2.1
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleFinancial Services Enterprise Case Management>= 8.1.1.0, <= 8.1.2.1
OracleFinancial Services Trade-Based Anti Money Laundering8.0.7
OracleGlobal Lifecycle Management Nextgen Oui Framework< 13.9.4.2.2
OracleGlobal Lifecycle Management Opatch< 12.2.0.1.30
OracleGraph Server And Client< 22.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-36518?

CVE-2020-36518 is a vulnerability with a CVSS score of 7.5 (HIGH). jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

How severe is CVE-2020-36518?

CVE-2020-36518 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-36518?

Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Oracle Big Data Spatial And Graph, Oracle Coherence, Oracle Commerce Platform, Oracle Communications Billing And Revenue Management.