CyberSec.Space Logo
CVEブラウザに戻る

CVE-2018-7489

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0800%
EPSS Percentile21.12th
Published2018年2月26日
Last Modified2024年11月21日

Vulnerability Description

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

Affected Platforms (CPE)

📦
Fasterxml

Jackson Databind

< 2.7.9.3
📦
Fasterxml

Jackson Databind

>= 2.8.0 and < 2.8.11.1
📦
Fasterxml

Jackson Databind

>= 2.9.0 and < 2.9.5
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
📦
Oracle

Communications Billing And Revenue Management

= 7.5
📦
Oracle

Communications Billing And Revenue Management

= 12.0
📦
Oracle

Communications Instant Messaging Server

= 10.0.1
📦
Redhat

Jboss Enterprise Application Platform

= 6.4.19
📦
Redhat

Jboss Enterprise Application Platform

= 7.1.2

References & Advisories

関連する脆弱性情報