Service Level Manager
NetApp · 29 CVEs
RCE from attacker with configuration edit priviledges through JNDI lookup
Dec 16, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing
Jan 19, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commo…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.de…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.de…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbc…
Jan 6, 2021
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded…
Dec 27, 2020
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Dec 17, 2020
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.db…
Dec 17, 2020
jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)
Dec 3, 2020
wildfly-core: memory leak in WildFly host-controller in domain mode while not able to reconnect to domain-controller
Oct 30, 2020
wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL
Oct 6, 2020
jackson-databind: Lacks certain xbean-reflect/JNDI blocking
Feb 10, 2020
jackson-databind: lacks certain net.sf.ehcache blocking
Jan 3, 2020
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and result…
Oct 8, 2019
jackson-databind: Serialization gadgets in classes of the ehcache package
Oct 6, 2019
jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource
Oct 1, 2019
jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*
Oct 1, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-42550 | RCE from attacker with configuration edit priviledges through JNDI lookup | MEDIUM | 4.44% | Dec 16, 2021 |
| CVE-2021-20190 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing | HIGH | 7.48% | Jan 19, 2021 |
| CVE-2020-36179 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 17.07% | Jan 6, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-36183 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool | HIGH | 4.97% | Jan 6, 2021 |
| CVE-2020-36184 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.36% | Jan 6, 2021 |
| CVE-2020-36185 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36186 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36187 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource | HIGH | 4.24% | Jan 6, 2021 |
| CVE-2020-36188 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnection… | HIGH | 8.79% | Jan 6, 2021 |
| CVE-2020-36189 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC… | HIGH | 3.99% | Jan 6, 2021 |
| CVE-2020-36181 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 4.09% | Jan 6, 2021 |
| CVE-2020-35728 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnection… | HIGH | 12.50% | Dec 27, 2020 |
| CVE-2020-35490 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource | HIGH | 6.29% | Dec 17, 2020 |
| CVE-2020-35491 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource | HIGH | 7.75% | Dec 17, 2020 |
| CVE-2020-25649 | jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) | HIGH | 17.26% | Dec 3, 2020 |
| CVE-2020-25689 | wildfly-core: memory leak in WildFly host-controller in domain mode while not able to reconnect to domain-controller | MEDIUM | 1.50% | Oct 30, 2020 |
| CVE-2020-25644 | wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL | HIGH | 2.37% | Oct 6, 2020 |
| CVE-2020-8840 | jackson-databind: Lacks certain xbean-reflect/JNDI blocking | CRITICAL | 26.59% | Feb 10, 2020 |
| CVE-2019-20330 | jackson-databind: lacks certain net.sf.ehcache blocking | CRITICAL | 8.64% | Jan 3, 2020 |
| CVE-2019-17359 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted… | HIGH | 8.95% | Oct 8, 2019 |
| CVE-2019-17267 | jackson-databind: Serialization gadgets in classes of the ehcache package | CRITICAL | 4.63% | Oct 6, 2019 |
| CVE-2019-16943 | jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource | CRITICAL | 4.90% | Oct 1, 2019 |
| CVE-2019-16942 | jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* | CRITICAL | 5.73% | Oct 1, 2019 |
Showing 1 to 25 of 29 CVEs