CVE-2019-20330
Description
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.863
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Oracle WebLogic Server 12.2.1.4.0 | Windows |
| Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0 | Windows |
| Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0 | Windows |
| Vulnerabilities CVE-2020-25649,CVE-2020-10673,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind 2.6.7.4 | Windows |
| Multiple vulnerabilities are fixed in Jackson-databind 2.8.11.5 | Windows |
| Vulnerabilities CVE-2020-9547,CVE-2020-9548,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind 2.7.9.7 | Windows |
| Vulnerabilities CVE-2019-20330 are fixed in Jackson-databind 2.9.10.2 | Windows |
| Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.5 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.2 | Windows |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) slf4j-1.7.25-4.module+el8.5.0+697+f586bb30.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) velocity-1.7-24.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xalan-j2-2.7.1-38.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) javassist-3.18.1-8.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xerces-j2-2.11.0-34.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) javassist-javadoc-3.18.1-8.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) apache-commons-lang-2.6-21.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xml-commons-resolver-1.2-26.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) apache-commons-collections-3.2.2-10.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) jakarta-commons-httpclient-3.1-28.module+el8.3.0+53+ea062990.noarch.rpm | Linux |
| Vulnerabilities CVE-2020-25649,CVE-2020-10673,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind for Linux 2.6.7.4 | Linux |
| Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.8.11.5 | Linux |
| Vulnerabilities CVE-2020-9547,CVE-2020-9548,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind for Linux 2.7.9.7 | Linux |
| Vulnerabilities CVE-2019-20330 are fixed in Jackson-databind for Linux 2.9.10.2 | Linux |
| Deserialization of Untrusted Data Vulnerability (CVE-2019-20330) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234