imPC@ndo IT

Tracker / CVE-2019-14439

CVE-2019-14439

High 7.5

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

Affected products and versions

apache drill
debian debian_linux
fasterxml jackson-databind · 2.0.0 → 2.6.7.3
fasterxml jackson-databind · 2.7.0 → 2.7.9.6
fasterxml jackson-databind · 2.8.0 → 2.8.11.4
fasterxml jackson-databind · 2.9.0 → 2.9.9.2
fedoraproject fedora
oracle banking_platform
oracle communications_diameter_signaling_router
oracle communications_instant_messaging_server
oracle financial_services_analytical_applications_infrastructure · 8.0.2 → 8.0.8
oracle global_lifecycle_management_opatch
oracle global_lifecycle_management_opatch · … → 11.2.0.3.23
oracle global_lifecycle_management_opatch · 12.2.0.1.0 → 12.2.0.1.19
oracle global_lifecycle_management_opatch · 13.9.4.0.0 → 13.9.4.2.1
oracle goldengate_stream_analytics · … → 19.1.0.0.1
oracle jd_edwards_enterpriseone_orchestrator
oracle jd_edwards_enterpriseone_tools
oracle primavera_gateway
oracle primavera_gateway · 17.7 → 17.12
oracle retail_customer_management_and_segmentation_foundation
oracle retail_xstore_point_of_service
oracle siebel_engineering_-_installer_\&_deployment · … → 19.8
oracle siebel_ui_framework · … → 19.10
redhat jboss_middleware_text-only_advisories

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References