CVE-2018-19360
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
Affected Platforms (CPE)
📦
Fasterxml
Jackson Databind
>= 2.6.0 and <= 2.6.7.2📦
Fasterxml
Jackson Databind
>= 2.7.0 and < 2.7.9.5📦
Fasterxml
Jackson Databind
>= 2.8.0 and < 2.8.11.3📦
Fasterxml
Jackson Databind
>= 2.9.0 and < 2.9.8💻
Debian
Debian Linux
= 8.0📦
Oracle
Business Process Management Suite
= 12.1.3.0.0📦
Oracle
Business Process Management Suite
= 12.2.1.3.0📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
>= 17.7 and <= 17.12📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 15.1📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 15.2📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 16.1📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 16.2📦
Oracle
Primavera P6 Enterprise Project Portfolio Management
= 18.8📦
Oracle
Primavera Unifier
>= 17.7 and <= 17.12📦
Oracle
Primavera Unifier
= 16.1📦
Oracle
Primavera Unifier
= 16.2📦
Oracle
Primavera Unifier
= 18.8📦
Oracle
Retail Workforce Management Software
= 1.60.9.0.0📦
Oracle
Webcenter Portal
= 12.2.1.3.0📦
Redhat
Automation Manager
= 7.3.1📦
Redhat
Decision Manager
= 7.3.1📦
Redhat
Jboss Bpm Suite
= 6.4.11📦
Redhat
Jboss Brms
= 6.4.10📦
Redhat
