CVE-2018-19360
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
Affected Platforms (CPE)
π¦
Fasterxml
Jackson Databind
>= 2.6.0 and <= 2.6.7.2π¦
Fasterxml
Jackson Databind
>= 2.7.0 and < 2.7.9.5π¦
Fasterxml
Jackson Databind
>= 2.8.0 and < 2.8.11.3π¦
Fasterxml
Jackson Databind
>= 2.9.0 and < 2.9.8π»
Debian
Debian Linux
= 8.0π¦
Oracle
Business Process Management Suite
= 12.1.3.0.0π¦
Oracle
Business Process Management Suite
= 12.2.1.3.0π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
>= 17.7 and <= 17.12π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 15.1π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 15.2π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 16.1π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 16.2π¦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 18.8π¦
Oracle
Primavera Unifier
>= 17.7 and <= 17.12π¦
Oracle
Primavera Unifier
= 16.1π¦
Oracle
Primavera Unifier
= 16.2π¦
Oracle
Primavera Unifier
= 18.8π¦
Oracle
Retail Workforce Management Software
= 1.60.9.0.0π¦
Oracle
Webcenter Portal
= 12.2.1.3.0π¦
Redhat
Automation Manager
= 7.3.1π¦
Redhat
Decision Manager
= 7.3.1π¦
Redhat
Jboss Bpm Suite
= 6.4.11π¦
Redhat
Jboss Brms
= 6.4.10π¦
Redhat
