CVE Database
/

CVE-2018-7489

Back to search

CVE-2018-7489

Published: Feb 26, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

VendorProductVersions

n/a

n/a

affected
n/a

References

103203
vdb-entry
x_refsource_BID
RHSA-2018:1448
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1449
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2938
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1450
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2090
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2939
vendor-advisory
x_refsource_REDHAT
1041890
vdb-entry
x_refsource_SECTRACK
1040693
vdb-entry
x_refsource_SECTRACK
RHSA-2018:1786
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1451
vendor-advisory
x_refsource_REDHAT
DSA-4190
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:1447
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2088
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2089
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2858
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3149
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now