CVE-2019-12814

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
18.339

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Jackson-databind 2.6.7.3Windows
Vulnerabilities CVE-2019-14439,CVE-2019-14379,CVE-2019-12814,CVE-2019-12384,CVE-2019-12086 are fixed in Jackson-databind 2.7.9.6Windows
Vulnerabilities CVE-2019-14439,CVE-2019-14379,CVE-2019-12814,CVE-2019-12384,CVE-2019-12086 are fixed in Jackson-databind 2.8.11.4Windows
Vulnerabilities CVE-2019-12814,CVE-2019-12384 are fixed in Jackson-databind 2.9.9.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.0.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.4Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.5.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.6.7.3Linux
Vulnerabilities CVE-2019-14439,CVE-2019-14379,CVE-2019-12814,CVE-2019-12384,CVE-2019-12086 are fixed in Jackson-databind for Linux 2.7.9.6Linux
Vulnerabilities CVE-2019-14439,CVE-2019-14379,CVE-2019-12814,CVE-2019-12384,CVE-2019-12086 are fixed in Jackson-databind for Linux 2.8.11.4Linux
Vulnerabilities CVE-2019-12814,CVE-2019-12384 are fixed in Jackson-databind for Linux 2.9.9.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234