CVE-2018-19362

Description

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.079

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Jackson-databind 2.6.7.3Windows
Multiple vulnerabilities are fixed in Jackson-databind 2.8.11.3Windows
Multiple vulnerabilities are fixed in Jackson-databind 2.7.9.5Windows
Vulnerabilities CVE-2018-19362,CVE-2018-19361,CVE-2018-19360 are fixed in Jackson-databind 2.9.8Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.1Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.2Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 16.1Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 16.2Windows
Vulnerabilities CVE-2016-1000031,CVE-2018-0732,CVE-2018-0734,CVE-2018-19362,CVE-2019-2512 are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 17.12Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 18.8Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 15.2Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 16.1Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 16.2Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 17.12Windows
Multiple Vulnerabilities are affected in Oracle Corporation Primavera P6 Enterprise Project Portfolio Management 18.8Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.6.7.3Linux
Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.8.11.3Linux
Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.7.9.5Linux
Vulnerabilities CVE-2018-19362,CVE-2018-19361,CVE-2018-19360 are fixed in Jackson-databind for Linux 2.9.8Linux
Deserialization of Untrusted Data Vulnerability (CVE-2018-19362)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234