Back

HIGH

jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver

Published Mar 17, 2019

Description

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6 is not affected by this issue, since Candlepin's java runtime environment does not load Oracle's JDBC classes. Red Hat Virtualization 4 is not affected by this issue, since it does not load Oracle's JDBC classes. Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.

References (50)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Mar 17, 2019
Updated Aug 5, 2024
Reserved Jun 7, 2018

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Jun 8, 2018
Bugzilla 1671096

ENISA EUVD

Assigner mitre
Published Mar 17, 2019
Updated Aug 5, 2024