CyberSec.Space Logo
Back to CVE Browser

CVE-2017-17485

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0760%
EPSS Percentile40.02th
PublishedJan 10, 2018
Last ModifiedAug 27, 2025

Vulnerability Description

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

Affected Platforms (CPE)

πŸ“¦
Fasterxml

Jackson Databind

< 2.6.7.3
πŸ“¦
Fasterxml

Jackson Databind

>= 2.7.0 and < 2.7.9.2
πŸ“¦
Fasterxml

Jackson Databind

>= 2.8.0 and < 2.8.11
πŸ“¦
Fasterxml

Jackson Databind

>= 2.9.0 and < 2.9.4
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 6.0.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 6.4.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 7.1
πŸ“¦
Redhat

Openshift Container Platform

= 4.1
πŸ“¦
Redhat

Openshift Container Platform

= 3.11
πŸ“¦
Netapp

E Series Santricity Os Controller

>= 11.0.0 and <= 11.60.3
πŸ“¦
Netapp

E Series Santricity Web Services Proxy

All versions
πŸ“¦
Netapp

Oncommand Shift

All versions
πŸ“¦
Netapp

Snapcenter

All versions

References & Advisories

Related Vulnerabilities