2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2018-14721" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2019-01-02T18:29:00.543" ,
2023-11-07 21:03:21 +00:00
"lastModified" : "2023-11-07T02:53:01.290" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization."
} ,
{
"lang" : "es" ,
"value" : "Las versiones 2.x de FasterXML jackson-databind anteriores a la 2.9.7 podr\u00edan permitir a los atacantes remotos realizar ataques de SSRF (Server-Side Request Forgery) aprovechando un fallo para bloquear la clase axis2-ext de deserializaci\u00f3n polim\u00f3rfica."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 10.0 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 6.0
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "PARTIAL" ,
"baseScore" : 7.5
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-918"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.6.0" ,
"versionEndExcluding" : "2.6.7.2" ,
"matchCriteriaId" : "A1BA8F04-46A7-4804-A997-59080034013F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.7.0" ,
"versionEndExcluding" : "2.7.9.5" ,
"matchCriteriaId" : "B99066EB-FF79-4D9D-9466-B04AD4D3A814"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.8.0" ,
"versionEndExcluding" : "2.8.11.3" ,
"matchCriteriaId" : "F4D3858C-DAF3-4522-90EC-EFCD13BD121E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.9.0" ,
"versionEndExcluding" : "2.9.7" ,
"matchCriteriaId" : "4DA01839-5250-43A7-AFB7-871DC9B8AB32"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "C43DF125-AD83-4402-BF82-72542F898D6D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "E2DD9CB6-7456-417A-A816-32BD8EC5FA83"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "80428392-1050-4980-BF13-49CE32F96478"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "ADA0D863-2917-4E7B-8FF6-B499180D2D4C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "ED1E9904-73E0-45F3-86A9-6173EE67E74D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1618FF9-0FDC-44BA-9FDA-5EA843C0D2D5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr2:*:*:*:*:*:*" ,
"matchCriteriaId" : "3FEDB0BC-FE4C-4851-A142-96767E337898"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr3:*:*:*:*:*:*" ,
"matchCriteriaId" : "75836E44-81A6-42C0-A589-A990887C7F9B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr4:*:*:*:*:*:*" ,
"matchCriteriaId" : "F794F46D-8B49-43FE-9EE0-4ECD20F9BCB0"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DEECE5FC-CACF-4496-A3E7-164736409252"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "35AD0C07-9688-4397-8D45-FBB88C0F0C11"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8972497F-6E24-45A9-9A18-EB0E842CB1D4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "400509A8-D6F2-432C-A2F1-AD5B8778D0D9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "132CE62A-FBFC-4001-81EC-35D81F73AF48"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6039DC7-08F2-4DD9-B5B5-B6B22DD2409F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7231AF76-3D46-41C4-83E9-6E9E12940BD9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A9E97F04-00ED-48E9-AB40-7A02B3419641"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FCCE5A11-39E7-4BBB-9E1A-BA4B754103BB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A5AEC7F5-C353-4CF5-96CE-8C713A2B0C92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB79BB43-E0AB-4F0D-A6EA-000485757EEC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F238CB66-886D-47E8-8DC0-7FC2025771EB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "59B7B8AD-1210-4C40-8EF7-E2E8156630A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0DE4A291-4358-42A9-A68D-E59D9998A1CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D19CF00-FE20-4690-AAB7-8E9DBC68A94F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A030A498-3361-46F8-BB99-24A66CAE11CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "042C243F-EDFE-4A04-AB0B-26E73CC34837"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "228DA523-4D6D-48C5-BDB0-DB1A60F23F8B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "17.1" ,
"versionEndIncluding" : "17.12" ,
"matchCriteriaId" : "B8249A74-C34A-4F66-8F11-F7F50F8813BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D55A54FD-7DD1-49CD-BE81-0BE73990943C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "82EB08C0-2D46-4635-88DF-E54F6452D3A3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "202AD518-2E9B-4062-B063-9858AE1F9CE2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "792DF04A-2D1B-40B5-B960-3E7152732EB8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_merchandising_system:16.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "46525CA6-4226-4F6F-B899-D800D4DDE0B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6A4F71A-4269-40FC-8F61-1D1301F2B728"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0952BA1A-5DF9-400F-B01F-C3A398A8A2D4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2F87326E-0B56-4356-A889-73D026DB1D4B"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://access.redhat.com/errata/RHBA-2019:0959" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:0782" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1106" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1107" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1108" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1140" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1822" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:1823" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:2858" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:3149" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:3892" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2019:4037" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/FasterXML/jackson-databind/issues/2097" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Issue Tracking" ,
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Release Notes" ,
"Third Party Advisory"
]
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E" ,
2023-04-24 12:24:31 +02:00
"source" : "cve@mitre.org"
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E" ,
2023-04-24 12:24:31 +02:00
"source" : "cve@mitre.org"
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E" ,
2023-04-24 12:24:31 +02:00
"source" : "cve@mitre.org"
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E" ,
"source" : "cve@mitre.org"
2023-04-24 12:24:31 +02:00
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E" ,
2023-04-24 12:24:31 +02:00
"source" : "cve@mitre.org"
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://seclists.org/bugtraq/2019/May/68" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20190530-0003/" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.debian.org/security/2019/dsa-4452" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/security-alerts/cpuapr2020.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" ,
"source" : "cve@mitre.org"
}
]
}