CVE-2017-7525

Description

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
79.267

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.1.3.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 10.3.6.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.2Windows
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind 2.6.7.1Windows
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind 2.7.9.1Windows
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind 2.8.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.12.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 6.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 6.4.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.1.0Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Balance 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Shift 2.3Windows
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Python-twisted-web security update (CESA-2016:1978) python-twisted-web-12.1.0-5.el7_2.x86_64.rpmLinux
(RHSA-2016:1978) Important: python-twisted-web security update python-twisted-web-12.1.0-5.el7_2.x86_64.rpmLinux
Suite of data-processing tools for Java (USN-4741-1) libjackson-json-java_1.9.2-7ubuntu0.2_all.debLinux
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind for Linux 2.6.7.1Linux
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind for Linux 2.7.9.1Linux
Vulnerabilities CVE-2017-7525 are fixed in Jackson-databind for Linux 2.8.9Linux
CVE-2017-7525NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234