CyberSec.Space Logo
Back to CVE Browser

CVE-2017-15095

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0220%
EPSS Percentile11.37th
PublishedFeb 6, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Affected Platforms (CPE)

πŸ“¦
Fasterxml

Jackson Databind

>= 2.0.0 and < 2.6.7.2
πŸ“¦
Fasterxml

Jackson Databind

>= 2.7.0 and < 2.7.9.2
πŸ“¦
Fasterxml

Jackson Databind

>= 2.8.0 and < 2.8.10
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ“¦
Redhat

Openshift Container Platform

= 3.11
πŸ“¦
Redhat

Satellite

= 6.4
πŸ“¦
Redhat

Satellite Capsule

= 6.4
πŸ“¦
Redhat

Openshift Container Platform

= 4.1
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 6.0.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 6.4.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 7.1.0
πŸ“¦
Netapp

Oncommand Balance

All versions
πŸ“¦
Netapp

Oncommand Performance Manager

All versions
πŸ“¦
Netapp

Oncommand Performance Manager

All versions
πŸ“¦
Netapp

Oncommand Shift

All versions
πŸ“¦
Netapp

Snapcenter

All versions
πŸ“¦
Oracle

Banking Platform

= 2.5.0
πŸ“¦
Oracle

Banking Platform

= 2.6.0
πŸ“¦
Oracle

Banking Platform

= 2.6.1
πŸ“¦
Oracle

Banking Platform

= 2.6.2
πŸ“¦
Oracle

Clusterware

= 12.1.0.2.0
πŸ“¦
Oracle

Communications Billing And Revenue Management

= 7.5
πŸ“¦
Oracle

Communications Billing And Revenue Management

= 12.0
πŸ“¦
Oracle

Communications Diameter Signaling Router

< 8.3
πŸ“¦
Oracle

Communications Instant Messaging Server

= 10.0.1.2.0
πŸ“¦
Oracle

Database Server

= 12.2.0.1
πŸ“¦
Oracle

Database Server

= 18.1
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.2.2
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.2.3
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.3.1
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.2
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.3
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.4
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.5
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.6
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.7
πŸ“¦
Oracle

Global Lifecycle Management Opatchauto

< 12.2.0.1.14
πŸ“¦
Oracle

Identity Manager

= 11.1.2.3.0
πŸ“¦
Oracle

Identity Manager

= 12.2.1.3.0
πŸ“¦
Oracle

Jd Edwards Enterpriseone Tools

= 9.2
πŸ“¦
Oracle

Primavera Unifier

>= 17.1 and <= 17.12
πŸ“¦
Oracle

Primavera Unifier

= 16.1
πŸ“¦
Oracle

Primavera Unifier

= 16.2
πŸ“¦
Oracle

Primavera Unifier

= 18.8
πŸ“¦
Oracle

Utilities Advanced Spatial And Operational Analytics

= 2.7.0.1
πŸ“¦
Oracle

Webcenter Portal

= 12.2.1.3.0

References & Advisories

Related Vulnerabilities