CVE-2018-1000873

Description

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.189

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Oracle 12.1.0.2Windows
Multiple Vulnerabilities are affected in Oracle 12.2.0.1Windows
Multiple Vulnerabilities are affected in Oracle 18cWindows
Multiple Vulnerabilities are affected in Oracle 19cWindows
Vulnerabilities CVE-2018-1000873 are fixed in FasterXML-jackson-datatype-jsr310 2.9.8Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.0Windows
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Vulnerabilities CVE-2018-1000873 are fixed in FasterXML-jackson-datatype-jsr310 for Linux 2.9.8Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234