Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-11307
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.126
EPSS Ranking
93.6%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
https://access.redhat.com/errata/RHSA-2019:0782
https://access.redhat.com/errata/RHSA-2019:1822
https://access.redhat.com/errata/RHSA-2019:1823
https://access.redhat.com/errata/RHSA-2019:2804
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3002
https://access.redhat.com/errata/RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3149
https://access.redhat.com/errata/RHSA-2019:3892
https://access.redhat.com/errata/RHSA-2019:4037
https://github.com/FasterXML/jackson-databind/issues/2032
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
https://nvd.nist.gov/vuln/detail/CVE-2017-7525
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://access.redhat.com/errata/RHSA-2019:0782
https://access.redhat.com/errata/RHSA-2019:1822
https://access.redhat.com/errata/RHSA-2019:1823
https://access.redhat.com/errata/RHSA-2019:2804
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3002
https://access.redhat.com/errata/RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3149
https://access.redhat.com/errata/RHSA-2019:3892
https://access.redhat.com/errata/RHSA-2019:4037
https://github.com/FasterXML/jackson-databind/issues/2032
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
https://nvd.nist.gov/vuln/detail/CVE-2017-7525
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Products affected by CVE-2018-11307
Fasterxml
»
Jackson-Databind
»
Version:
2.0.0
cpe:2.3:a:fasterxml:jackson-databind:2.0.0
Fasterxml
»
Jackson-Databind
»
Version:
2.0.1
cpe:2.3:a:fasterxml:jackson-databind:2.0.1
Fasterxml
»
Jackson-Databind
»
Version:
2.0.2
cpe:2.3:a:fasterxml:jackson-databind:2.0.2
Fasterxml
»
Jackson-Databind
»
Version:
2.0.4
cpe:2.3:a:fasterxml:jackson-databind:2.0.4
Fasterxml
»
Jackson-Databind
»
Version:
2.0.5
cpe:2.3:a:fasterxml:jackson-databind:2.0.5
Fasterxml
»
Jackson-Databind
»
Version:
2.0.6
cpe:2.3:a:fasterxml:jackson-databind:2.0.6
Fasterxml
»
Jackson-Databind
»
Version:
2.1.0
cpe:2.3:a:fasterxml:jackson-databind:2.1.0
Fasterxml
»
Jackson-Databind
»
Version:
2.1.1
cpe:2.3:a:fasterxml:jackson-databind:2.1.1
Fasterxml
»
Jackson-Databind
»
Version:
2.1.2
cpe:2.3:a:fasterxml:jackson-databind:2.1.2
Fasterxml
»
Jackson-Databind
»
Version:
2.1.3
cpe:2.3:a:fasterxml:jackson-databind:2.1.3
Fasterxml
»
Jackson-Databind
»
Version:
2.1.4
cpe:2.3:a:fasterxml:jackson-databind:2.1.4
Fasterxml
»
Jackson-Databind
»
Version:
2.1.5
cpe:2.3:a:fasterxml:jackson-databind:2.1.5
Fasterxml
»
Jackson-Databind
»
Version:
2.2.0
cpe:2.3:a:fasterxml:jackson-databind:2.2.0
Fasterxml
»
Jackson-Databind
»
Version:
2.2.1
cpe:2.3:a:fasterxml:jackson-databind:2.2.1
Fasterxml
»
Jackson-Databind
»
Version:
2.2.2
cpe:2.3:a:fasterxml:jackson-databind:2.2.2
Fasterxml
»
Jackson-Databind
»
Version:
2.2.3
cpe:2.3:a:fasterxml:jackson-databind:2.2.3
Fasterxml
»
Jackson-Databind
»
Version:
2.2.4
cpe:2.3:a:fasterxml:jackson-databind:2.2.4
Fasterxml
»
Jackson-Databind
»
Version:
2.3.0
cpe:2.3:a:fasterxml:jackson-databind:2.3.0
Fasterxml
»
Jackson-Databind
»
Version:
2.3.1
cpe:2.3:a:fasterxml:jackson-databind:2.3.1
Fasterxml
»
Jackson-Databind
»
Version:
2.3.2
cpe:2.3:a:fasterxml:jackson-databind:2.3.2
Fasterxml
»
Jackson-Databind
»
Version:
2.3.3
cpe:2.3:a:fasterxml:jackson-databind:2.3.3
Fasterxml
»
Jackson-Databind
»
Version:
2.3.4
cpe:2.3:a:fasterxml:jackson-databind:2.3.4
Fasterxml
»
Jackson-Databind
»
Version:
2.3.5
cpe:2.3:a:fasterxml:jackson-databind:2.3.5
Fasterxml
»
Jackson-Databind
»
Version:
2.4.0
cpe:2.3:a:fasterxml:jackson-databind:2.4.0
Fasterxml
»
Jackson-Databind
»
Version:
2.4.1
cpe:2.3:a:fasterxml:jackson-databind:2.4.1
Fasterxml
»
Jackson-Databind
»
Version:
2.4.1.1
cpe:2.3:a:fasterxml:jackson-databind:2.4.1.1
Fasterxml
»
Jackson-Databind
»
Version:
2.4.1.2
cpe:2.3:a:fasterxml:jackson-databind:2.4.1.2
Fasterxml
»
Jackson-Databind
»
Version:
2.4.1.3
cpe:2.3:a:fasterxml:jackson-databind:2.4.1.3
Fasterxml
»
Jackson-Databind
»
Version:
2.4.2
cpe:2.3:a:fasterxml:jackson-databind:2.4.2
Fasterxml
»
Jackson-Databind
»
Version:
2.4.3
cpe:2.3:a:fasterxml:jackson-databind:2.4.3
Fasterxml
»
Jackson-Databind
»
Version:
2.4.4
cpe:2.3:a:fasterxml:jackson-databind:2.4.4
Fasterxml
»
Jackson-Databind
»
Version:
2.4.5
cpe:2.3:a:fasterxml:jackson-databind:2.4.5
Fasterxml
»
Jackson-Databind
»
Version:
2.4.5.1
cpe:2.3:a:fasterxml:jackson-databind:2.4.5.1
Fasterxml
»
Jackson-Databind
»
Version:
2.4.6
cpe:2.3:a:fasterxml:jackson-databind:2.4.6
Fasterxml
»
Jackson-Databind
»
Version:
2.4.6.1
cpe:2.3:a:fasterxml:jackson-databind:2.4.6.1
Fasterxml
»
Jackson-Databind
»
Version:
2.5.0
cpe:2.3:a:fasterxml:jackson-databind:2.5.0
Fasterxml
»
Jackson-Databind
»
Version:
2.5.1
cpe:2.3:a:fasterxml:jackson-databind:2.5.1
Fasterxml
»
Jackson-Databind
»
Version:
2.5.2
cpe:2.3:a:fasterxml:jackson-databind:2.5.2
Fasterxml
»
Jackson-Databind
»
Version:
2.5.3
cpe:2.3:a:fasterxml:jackson-databind:2.5.3
Fasterxml
»
Jackson-Databind
»
Version:
2.5.4
cpe:2.3:a:fasterxml:jackson-databind:2.5.4
Fasterxml
»
Jackson-Databind
»
Version:
2.5.5
cpe:2.3:a:fasterxml:jackson-databind:2.5.5
Fasterxml
»
Jackson-Databind
»
Version:
2.6.0
cpe:2.3:a:fasterxml:jackson-databind:2.6.0
Fasterxml
»
Jackson-Databind
»
Version:
2.6.1
cpe:2.3:a:fasterxml:jackson-databind:2.6.1
Fasterxml
»
Jackson-Databind
»
Version:
2.6.2
cpe:2.3:a:fasterxml:jackson-databind:2.6.2
Fasterxml
»
Jackson-Databind
»
Version:
2.6.3
cpe:2.3:a:fasterxml:jackson-databind:2.6.3
Fasterxml
»
Jackson-Databind
»
Version:
2.6.4
cpe:2.3:a:fasterxml:jackson-databind:2.6.4
Fasterxml
»
Jackson-Databind
»
Version:
2.6.5
cpe:2.3:a:fasterxml:jackson-databind:2.6.5
Fasterxml
»
Jackson-Databind
»
Version:
2.6.6
cpe:2.3:a:fasterxml:jackson-databind:2.6.6
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7
cpe:2.3:a:fasterxml:jackson-databind:2.6.7
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7.1
cpe:2.3:a:fasterxml:jackson-databind:2.6.7.1
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7.2
cpe:2.3:a:fasterxml:jackson-databind:2.6.7.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.0
cpe:2.3:a:fasterxml:jackson-databind:2.7.0
Fasterxml
»
Jackson-Databind
»
Version:
2.7.1
cpe:2.3:a:fasterxml:jackson-databind:2.7.1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.1-1
cpe:2.3:a:fasterxml:jackson-databind:2.7.1-1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.2
cpe:2.3:a:fasterxml:jackson-databind:2.7.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.3
cpe:2.3:a:fasterxml:jackson-databind:2.7.3
Fasterxml
»
Jackson-Databind
»
Version:
2.7.4
cpe:2.3:a:fasterxml:jackson-databind:2.7.4
Fasterxml
»
Jackson-Databind
»
Version:
2.7.5
cpe:2.3:a:fasterxml:jackson-databind:2.7.5
Fasterxml
»
Jackson-Databind
»
Version:
2.7.6
cpe:2.3:a:fasterxml:jackson-databind:2.7.6
Fasterxml
»
Jackson-Databind
»
Version:
2.7.7
cpe:2.3:a:fasterxml:jackson-databind:2.7.7
Fasterxml
»
Jackson-Databind
»
Version:
2.7.8
cpe:2.3:a:fasterxml:jackson-databind:2.7.8
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9
cpe:2.3:a:fasterxml:jackson-databind:2.7.9
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.1
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.2
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.3
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.3
Fasterxml
»
Jackson-Databind
»
Version:
2.8.0
cpe:2.3:a:fasterxml:jackson-databind:2.8.0
Fasterxml
»
Jackson-Databind
»
Version:
2.8.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.10
cpe:2.3:a:fasterxml:jackson-databind:2.8.10
Fasterxml
»
Jackson-Databind
»
Version:
2.8.11
cpe:2.3:a:fasterxml:jackson-databind:2.8.11
Fasterxml
»
Jackson-Databind
»
Version:
2.8.11.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.11.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.2
cpe:2.3:a:fasterxml:jackson-databind:2.8.2
Fasterxml
»
Jackson-Databind
»
Version:
2.8.3
cpe:2.3:a:fasterxml:jackson-databind:2.8.3
Fasterxml
»
Jackson-Databind
»
Version:
2.8.4
cpe:2.3:a:fasterxml:jackson-databind:2.8.4
Fasterxml
»
Jackson-Databind
»
Version:
2.8.5
cpe:2.3:a:fasterxml:jackson-databind:2.8.5
Fasterxml
»
Jackson-Databind
»
Version:
2.8.6
cpe:2.3:a:fasterxml:jackson-databind:2.8.6
Fasterxml
»
Jackson-Databind
»
Version:
2.8.7
cpe:2.3:a:fasterxml:jackson-databind:2.8.7
Fasterxml
»
Jackson-Databind
»
Version:
2.8.8
cpe:2.3:a:fasterxml:jackson-databind:2.8.8
Fasterxml
»
Jackson-Databind
»
Version:
2.8.8.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.8.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.9
cpe:2.3:a:fasterxml:jackson-databind:2.8.9
Fasterxml
»
Jackson-Databind
»
Version:
2.9.0
cpe:2.3:a:fasterxml:jackson-databind:2.9.0
Fasterxml
»
Jackson-Databind
»
Version:
2.9.1
cpe:2.3:a:fasterxml:jackson-databind:2.9.1
Fasterxml
»
Jackson-Databind
»
Version:
2.9.2
cpe:2.3:a:fasterxml:jackson-databind:2.9.2
Fasterxml
»
Jackson-Databind
»
Version:
2.9.3
cpe:2.3:a:fasterxml:jackson-databind:2.9.3
Fasterxml
»
Jackson-Databind
»
Version:
2.9.4
cpe:2.3:a:fasterxml:jackson-databind:2.9.4
Fasterxml
»
Jackson-Databind
»
Version:
2.9.5
cpe:2.3:a:fasterxml:jackson-databind:2.9.5
Oracle
»
Clusterware
»
Version:
12.1.0.2.0
cpe:2.3:a:oracle:clusterware:12.1.0.2.0
Oracle
»
Communications Instant Messaging Server
»
Version:
10.0.1.2.0
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.2.0
Oracle
»
Global Lifecycle Management Opatch
»
Version:
Any
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*
Oracle
»
Global Lifecycle Management Opatch
»
Version:
12.2.0.1.0
cpe:2.3:a:oracle:global_lifecycle_management_opatch:12.2.0.1.0
Oracle
»
Global Lifecycle Management Opatch
»
Version:
13.9.4.0.0
cpe:2.3:a:oracle:global_lifecycle_management_opatch:13.9.4.0.0
Oracle
»
Retail Customer Management And Segmentation Foundation
»
Version:
17.0
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0
Oracle
»
Utilities Advanced Spatial And Operational Analytics
»
Version:
2.7.0.1
cpe:2.3:a:oracle:utilities_advanced_spatial_and_operational_analytics:2.7.0.1
Redhat
»
Openshift Container Platform
»
Version:
3.11
cpe:2.3:a:redhat:openshift_container_platform:3.11
Redhat
»
Openshift Container Platform
»
Version:
4.1
cpe:2.3:a:redhat:openshift_container_platform:4.1
Redhat
»
Enterprise Linux
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux:7.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved