FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
02 Sep 2022, 15:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oracle agile Plm
Oracle banking Virtual Account Management |
|
CPE | cpe:2.3:a:oracle:banking_virtual_account_managemen:14.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_managemen:14.5:*:*:*:*:*:*:* |
cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:* |
References | (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory |
25 Jul 2022, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 May 2022, 20:50
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:* |
|
First Time |
Oracle blockchain Platform
Oracle webcenter Portal |
20 Apr 2022, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Mar 2022, 15:20
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory | |
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
References | (MISC) https://github.com/FasterXML/jackson-databind/issues/3004 - Issue Tracking, Patch, Third Party Advisory | |
First Time |
Oracle retail Merchandising System
Oracle banking Virtual Account Managemen Oracle communications Pricing Design Center Oracle retail Customer Management And Segmentation Foundation Oracle jd Edwards Enterpriseone Tools Oracle communications Convergent Charging Controller Oracle communications Instant Messaging Server Oracle primavera Gateway Oracle jd Edwards Enterpriseone Orchestrator Oracle goldengate Application Adapters Oracle communications Evolved Communications Application Server Oracle communications Policy Management Oracle application Testing Suite Oracle communications Session Report Manager Oracle retail Xstore Point Of Service Oracle banking Treasury Management Oracle communications Services Gatekeeper Oracle autovue For Agile Product Lifecycle Management Oracle communications Billing And Revenue Management Oracle insurance Policy Administration Oracle Oracle banking Supply Chain Finance Oracle communications Diameter Signaling Route Oracle communications Element Manager Oracle communications Network Charging And Control Netapp cloud Backup Oracle communications Offline Mediation Controller Oracle retail Service Backbone Oracle insurance Rules Palette Oracle commerce Platform Oracle banking Credit Facilities Process Management Oracle communications Session Route Manager Oracle primavera Unifier Oracle data Integrator Oracle banking Corporate Lending Process Management Oracle communications Unified Inventory Management Oracle communications Cloud Native Core Policy Oracle communications Cloud Native Core Unified Data Repository |
|
CPE | cpe:2.3:a:oracle:banking_supply_chain_finance:14.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_managemen:14.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_treasury_management:14.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:commerce_platform:11.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_policy_administration:11.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_policy_administration:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:16.0.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_rules_palette:11.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_managemen:14.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_supply_chain_finance:14.2:*:*:*:*:*:*:* cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_route:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_merchandising_system:15.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_supply_chain_finance:14.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:15.0.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_virtual_account_managemen:14.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:commerce_platform:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_rules_palette:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_convergent_charging_controller:12.0.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:20.12.0:*:*:*:*:*:*:* |
07 Feb 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
17 Nov 2021, 22:05
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2021.html - Third Party Advisory | |
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Third Party Advisory |
20 Oct 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Apr 2021, 17:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/FasterXML/jackson-databind/issues/3004 - Patch, Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html - Mitigation, Third Party Advisory |
24 Apr 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
10 Feb 2021, 14:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netapp:service_level_manager:-:*:*:*:*:*:*:* | |
References | (MLIST) https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436@%3Cissues.spark.apache.org%3E - Mailing List, Third Party Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20210205-0005/ - Third Party Advisory |
05 Feb 2021, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Jan 2021, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jan 2021, 18:26
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.1 |
07 Jan 2021, 16:00
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 - Exploit, Technical Description, Third Party Advisory | |
References | (MISC) https://github.com/FasterXML/jackson-databind/issues/3004 - Third Party Advisory | |
CPE | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CWE | CWE-502 |
07 Jan 2021, 00:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-01-07 00:15
Updated : 2022-09-02 15:35
NVD link : CVE-2020-36179
Mitre link : CVE-2020-36179
JSON object : View
Products Affected
oracle
- communications_session_report_manager
- insurance_rules_palette
- communications_pricing_design_center
- retail_service_backbone
- blockchain_platform
- retail_customer_management_and_segmentation_foundation
- communications_session_route_manager
- webcenter_portal
- retail_merchandising_system
- communications_diameter_signaling_route
- banking_supply_chain_finance
- communications_evolved_communications_application_server
- banking_treasury_management
- communications_element_manager
- communications_convergent_charging_controller
- communications_instant_messaging_server
- communications_cloud_native_core_policy
- jd_edwards_enterpriseone_tools
- jd_edwards_enterpriseone_orchestrator
- banking_corporate_lending_process_management
- banking_credit_facilities_process_management
- communications_services_gatekeeper
- insurance_policy_administration
- agile_plm
- communications_network_charging_and_control
- primavera_gateway
- primavera_unifier
- goldengate_application_adapters
- autovue_for_agile_product_lifecycle_management
- retail_xstore_point_of_service
- commerce_platform
- data_integrator
- communications_cloud_native_core_unified_data_repository
- communications_billing_and_revenue_management
- communications_policy_management
- banking_virtual_account_management
- communications_offline_mediation_controller
- application_testing_suite
- communications_unified_inventory_management
netapp
- service_level_manager
- cloud_backup
debian
- debian_linux
fasterxml
- jackson-databind
CWE
CWE-502
Deserialization of Untrusted Data