Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-19361
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.049
EPSS Ranking
89.1%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://www.securityfocus.com/bid/107985
https://access.redhat.com/errata/RHBA-2019:0959
https://access.redhat.com/errata/RHSA-2019:0782
https://access.redhat.com/errata/RHSA-2019:0877
https://access.redhat.com/errata/RHSA-2019:1782
https://access.redhat.com/errata/RHSA-2019:1797
https://access.redhat.com/errata/RHSA-2019:1822
https://access.redhat.com/errata/RHSA-2019:1823
https://access.redhat.com/errata/RHSA-2019:2804
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3002
https://access.redhat.com/errata/RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3149
https://access.redhat.com/errata/RHSA-2019:3892
https://access.redhat.com/errata/RHSA-2019:4037
https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
https://github.com/FasterXML/jackson-databind/issues/2186
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
https://issues.apache.org/jira/browse/TINKERPOP-2121
https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html
https://seclists.org/bugtraq/2019/May/68
https://security.netapp.com/advisory/ntap-20190530-0003/
https://www.debian.org/security/2019/dsa-4452
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
http://www.securityfocus.com/bid/107985
https://access.redhat.com/errata/RHBA-2019:0959
https://access.redhat.com/errata/RHSA-2019:0782
https://access.redhat.com/errata/RHSA-2019:0877
https://access.redhat.com/errata/RHSA-2019:1782
https://access.redhat.com/errata/RHSA-2019:1797
https://access.redhat.com/errata/RHSA-2019:1822
https://access.redhat.com/errata/RHSA-2019:1823
https://access.redhat.com/errata/RHSA-2019:2804
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3002
https://access.redhat.com/errata/RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3149
https://access.redhat.com/errata/RHSA-2019:3892
https://access.redhat.com/errata/RHSA-2019:4037
https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
https://github.com/FasterXML/jackson-databind/issues/2186
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
https://issues.apache.org/jira/browse/TINKERPOP-2121
https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html
https://seclists.org/bugtraq/2019/May/68
https://security.netapp.com/advisory/ntap-20190530-0003/
https://www.debian.org/security/2019/dsa-4452
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Products affected by CVE-2018-19361
Fasterxml
»
Jackson-Databind
»
Version:
2.6.0
cpe:2.3:a:fasterxml:jackson-databind:2.6.0
Fasterxml
»
Jackson-Databind
»
Version:
2.6.1
cpe:2.3:a:fasterxml:jackson-databind:2.6.1
Fasterxml
»
Jackson-Databind
»
Version:
2.6.2
cpe:2.3:a:fasterxml:jackson-databind:2.6.2
Fasterxml
»
Jackson-Databind
»
Version:
2.6.3
cpe:2.3:a:fasterxml:jackson-databind:2.6.3
Fasterxml
»
Jackson-Databind
»
Version:
2.6.4
cpe:2.3:a:fasterxml:jackson-databind:2.6.4
Fasterxml
»
Jackson-Databind
»
Version:
2.6.5
cpe:2.3:a:fasterxml:jackson-databind:2.6.5
Fasterxml
»
Jackson-Databind
»
Version:
2.6.6
cpe:2.3:a:fasterxml:jackson-databind:2.6.6
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7
cpe:2.3:a:fasterxml:jackson-databind:2.6.7
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7.1
cpe:2.3:a:fasterxml:jackson-databind:2.6.7.1
Fasterxml
»
Jackson-Databind
»
Version:
2.6.7.2
cpe:2.3:a:fasterxml:jackson-databind:2.6.7.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.0
cpe:2.3:a:fasterxml:jackson-databind:2.7.0
Fasterxml
»
Jackson-Databind
»
Version:
2.7.1
cpe:2.3:a:fasterxml:jackson-databind:2.7.1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.1-1
cpe:2.3:a:fasterxml:jackson-databind:2.7.1-1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.2
cpe:2.3:a:fasterxml:jackson-databind:2.7.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.3
cpe:2.3:a:fasterxml:jackson-databind:2.7.3
Fasterxml
»
Jackson-Databind
»
Version:
2.7.4
cpe:2.3:a:fasterxml:jackson-databind:2.7.4
Fasterxml
»
Jackson-Databind
»
Version:
2.7.5
cpe:2.3:a:fasterxml:jackson-databind:2.7.5
Fasterxml
»
Jackson-Databind
»
Version:
2.7.6
cpe:2.3:a:fasterxml:jackson-databind:2.7.6
Fasterxml
»
Jackson-Databind
»
Version:
2.7.7
cpe:2.3:a:fasterxml:jackson-databind:2.7.7
Fasterxml
»
Jackson-Databind
»
Version:
2.7.8
cpe:2.3:a:fasterxml:jackson-databind:2.7.8
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9
cpe:2.3:a:fasterxml:jackson-databind:2.7.9
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.1
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.1
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.2
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.2
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.3
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.3
Fasterxml
»
Jackson-Databind
»
Version:
2.7.9.4
cpe:2.3:a:fasterxml:jackson-databind:2.7.9.4
Fasterxml
»
Jackson-Databind
»
Version:
2.8.0
cpe:2.3:a:fasterxml:jackson-databind:2.8.0
Fasterxml
»
Jackson-Databind
»
Version:
2.8.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.10
cpe:2.3:a:fasterxml:jackson-databind:2.8.10
Fasterxml
»
Jackson-Databind
»
Version:
2.8.11
cpe:2.3:a:fasterxml:jackson-databind:2.8.11
Fasterxml
»
Jackson-Databind
»
Version:
2.8.11.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.11.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.11.2
cpe:2.3:a:fasterxml:jackson-databind:2.8.11.2
Fasterxml
»
Jackson-Databind
»
Version:
2.8.2
cpe:2.3:a:fasterxml:jackson-databind:2.8.2
Fasterxml
»
Jackson-Databind
»
Version:
2.8.3
cpe:2.3:a:fasterxml:jackson-databind:2.8.3
Fasterxml
»
Jackson-Databind
»
Version:
2.8.4
cpe:2.3:a:fasterxml:jackson-databind:2.8.4
Fasterxml
»
Jackson-Databind
»
Version:
2.8.5
cpe:2.3:a:fasterxml:jackson-databind:2.8.5
Fasterxml
»
Jackson-Databind
»
Version:
2.8.6
cpe:2.3:a:fasterxml:jackson-databind:2.8.6
Fasterxml
»
Jackson-Databind
»
Version:
2.8.7
cpe:2.3:a:fasterxml:jackson-databind:2.8.7
Fasterxml
»
Jackson-Databind
»
Version:
2.8.8
cpe:2.3:a:fasterxml:jackson-databind:2.8.8
Fasterxml
»
Jackson-Databind
»
Version:
2.8.8.1
cpe:2.3:a:fasterxml:jackson-databind:2.8.8.1
Fasterxml
»
Jackson-Databind
»
Version:
2.8.9
cpe:2.3:a:fasterxml:jackson-databind:2.8.9
Fasterxml
»
Jackson-Databind
»
Version:
2.9.0
cpe:2.3:a:fasterxml:jackson-databind:2.9.0
Fasterxml
»
Jackson-Databind
»
Version:
2.9.1
cpe:2.3:a:fasterxml:jackson-databind:2.9.1
Fasterxml
»
Jackson-Databind
»
Version:
2.9.2
cpe:2.3:a:fasterxml:jackson-databind:2.9.2
Fasterxml
»
Jackson-Databind
»
Version:
2.9.3
cpe:2.3:a:fasterxml:jackson-databind:2.9.3
Fasterxml
»
Jackson-Databind
»
Version:
2.9.4
cpe:2.3:a:fasterxml:jackson-databind:2.9.4
Fasterxml
»
Jackson-Databind
»
Version:
2.9.5
cpe:2.3:a:fasterxml:jackson-databind:2.9.5
Fasterxml
»
Jackson-Databind
»
Version:
2.9.6
cpe:2.3:a:fasterxml:jackson-databind:2.9.6
Fasterxml
»
Jackson-Databind
»
Version:
2.9.7
cpe:2.3:a:fasterxml:jackson-databind:2.9.7
Oracle
»
Business Process Management Suite
»
Version:
12.1.3.0.0
cpe:2.3:a:oracle:business_process_management_suite:12.1.3.0.0
Oracle
»
Business Process Management Suite
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
15.1
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.1
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
15.2
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.2
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
16.1
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:16.1
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
16.2
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:16.2
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.10
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.10
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.11
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.11
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.12
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.12
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.7
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.7
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.8
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.8
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
17.9
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:17.9
Oracle
»
Primavera P6 Enterprise Project Portfolio Management
»
Version:
18.8
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:18.8
Oracle
»
Primavera Unifier
»
Version:
16.1
cpe:2.3:a:oracle:primavera_unifier:16.1
Oracle
»
Primavera Unifier
»
Version:
16.2
cpe:2.3:a:oracle:primavera_unifier:16.2
Oracle
»
Primavera Unifier
»
Version:
17.10
cpe:2.3:a:oracle:primavera_unifier:17.10
Oracle
»
Primavera Unifier
»
Version:
17.11
cpe:2.3:a:oracle:primavera_unifier:17.11
Oracle
»
Primavera Unifier
»
Version:
17.12
cpe:2.3:a:oracle:primavera_unifier:17.12
Oracle
»
Primavera Unifier
»
Version:
17.7
cpe:2.3:a:oracle:primavera_unifier:17.7
Oracle
»
Primavera Unifier
»
Version:
17.8
cpe:2.3:a:oracle:primavera_unifier:17.8
Oracle
»
Primavera Unifier
»
Version:
17.9
cpe:2.3:a:oracle:primavera_unifier:17.9
Oracle
»
Primavera Unifier
»
Version:
18.8
cpe:2.3:a:oracle:primavera_unifier:18.8
Oracle
»
Retail Workforce Management Software
»
Version:
1.60.9.0.0
cpe:2.3:a:oracle:retail_workforce_management_software:1.60.9.0.0
Oracle
»
Webcenter Portal
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0
Redhat
»
Automation Manager
»
Version:
7.3.1
cpe:2.3:a:redhat:automation_manager:7.3.1
Redhat
»
Decision Manager
»
Version:
7.3.1
cpe:2.3:a:redhat:decision_manager:7.3.1
Redhat
»
Jboss Bpm Suite
»
Version:
6.4.11
cpe:2.3:a:redhat:jboss_bpm_suite:6.4.11
Redhat
»
Jboss Brms
»
Version:
6.4.10
cpe:2.3:a:redhat:jboss_brms:6.4.10
Redhat
»
Openshift Container Platform
»
Version:
3.11
cpe:2.3:a:redhat:openshift_container_platform:3.11
Debian
»
Debian Linux
»
Version:
8.0
cpe:2.3:o:debian:debian_linux:8.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved