CyberSec.Space Logo
Back to CVE Browser

CVE-2018-14721

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0110%
EPSS Percentile18.28th
PublishedJan 2, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

Affected Platforms (CPE)

πŸ“¦
Fasterxml

Jackson Databind

>= 2.6.0 and < 2.6.7.2
πŸ“¦
Fasterxml

Jackson Databind

>= 2.7.0 and < 2.7.9.5
πŸ“¦
Fasterxml

Jackson Databind

>= 2.8.0 and < 2.8.11.3
πŸ“¦
Fasterxml

Jackson Databind

>= 2.9.0 and < 2.9.7
πŸ“¦
Fasterxml

Jackson Databind

= 2.7.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.7.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.7.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.8.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.8.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ“¦
Fasterxml

Jackson Databind

= 2.9.0
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ“¦
Oracle

Banking Platform

= 2.5.0
πŸ“¦
Oracle

Banking Platform

= 2.6.0
πŸ“¦
Oracle

Banking Platform

= 2.6.1
πŸ“¦
Oracle

Banking Platform

= 2.6.2
πŸ“¦
Oracle

Communications Billing And Revenue Management

= 7.5
πŸ“¦
Oracle

Communications Billing And Revenue Management

= 12.0
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.2.2
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.2.3
πŸ“¦
Oracle

Enterprise Manager For Virtualization

= 13.3.1
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.2
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.3
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.4
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.5
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.6
πŸ“¦
Oracle

Financial Services Analytical Applications Infrastructure

= 8.0.7
πŸ“¦
Oracle

Jdeveloper

= 12.1.3.0.0
πŸ“¦
Oracle

Jdeveloper

= 12.2.1.3.0
πŸ“¦
Oracle

Primavera Unifier

>= 17.1 and <= 17.12
πŸ“¦
Oracle

Primavera Unifier

= 16.1
πŸ“¦
Oracle

Primavera Unifier

= 16.2
πŸ“¦
Oracle

Primavera Unifier

= 18.8
πŸ“¦
Oracle

Retail Merchandising System

= 15.0
πŸ“¦
Oracle

Retail Merchandising System

= 16.0
πŸ“¦
Oracle

Webcenter Portal

= 12.2.1.3.0
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 7.2.0
πŸ“¦
Redhat

Openshift Container Platform

= 3.11

References & Advisories

Related Vulnerabilities