CVE-2019-20330

Description

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.863

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Vulnerabilities CVE-2020-25649,CVE-2020-10673,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind 2.6.7.4Windows
Multiple vulnerabilities are fixed in Jackson-databind 2.8.11.5Windows
Vulnerabilities CVE-2020-9547,CVE-2020-9548,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind 2.7.9.7Windows
Vulnerabilities CVE-2019-20330 are fixed in Jackson-databind 2.9.10.2Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.5Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.2Windows
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) slf4j-1.7.25-4.module+el8.5.0+697+f586bb30.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) velocity-1.7-24.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xalan-j2-2.7.1-38.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) javassist-3.18.1-8.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xerces-j2-2.11.0-34.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) javassist-javadoc-3.18.1-8.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) apache-commons-lang-2.6-21.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) xml-commons-resolver-1.2-26.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) apache-commons-collections-3.2.2-10.module+el8.3.0+53+ea062990.noarch.rpmLinux
pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (RLSA-2020:1644) jakarta-commons-httpclient-3.1-28.module+el8.3.0+53+ea062990.noarch.rpmLinux
Vulnerabilities CVE-2020-25649,CVE-2020-10673,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind for Linux 2.6.7.4Linux
Multiple vulnerabilities are fixed in Jackson-databind for Linux 2.8.11.5Linux
Vulnerabilities CVE-2020-9547,CVE-2020-9548,CVE-2020-8840,CVE-2019-20330 are fixed in Jackson-databind for Linux 2.7.9.7Linux
Vulnerabilities CVE-2019-20330 are fixed in Jackson-databind for Linux 2.9.10.2Linux
Deserialization of Untrusted Data Vulnerability (CVE-2019-20330)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234