CVE-2019-20330

CVSS V2 High 7.5 CVSS V3 Critical 9.8
Description
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Overview
  • CVE ID
  • CVE-2019-20330
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-01-03T04:15:12
  • Last Modified Date
  • 2022-10-29T02:34:00
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 1 OR 2.7.0 2.7.9.7
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 1 OR 2.8.0 2.8.11.5
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 1 OR 2.9.0 2.9.10.2
cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* 1 OR 2.4.0 2.9.0
cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_contacts_server:8.0.0.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:* 1 OR 12.0.0 12.0.3
cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 1 OR 11.2.0.3.23
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 1 OR 12.2.0.1.0 12.2.0.1.19
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 1 OR 13.9.4.0.0 13.9.4.2.1
cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:goldengate_stream_analytics:*:*:*:*:*:*:*:* 1 OR 19.1.0.0.1
cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* 1 OR 9.2.4.2
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* 1 OR 9.2.4.2
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* 1 OR 17.7 17.12
cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_merchandising_system:15.0.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_merchandising_system:16.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:siebel_engineering_-_installer_\&_deployment:*:*:*:*:*:*:*:* 1 OR 2.20.5
cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:* 1 OR 20.5
cpe:2.3:a:oracle:trace_file_analyzer:12.2.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:trace_file_analyzer:18c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:trace_file_analyzer:19c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:* 1 OR 7.3
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* 1 OR 7.3
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* 1 OR 9.5
cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:service_level_manager:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
References
Reference URL Reference Tags
https://github.com/FasterXML/jackson-databind/issues/2526 Patch Third Party Advisory
https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2 Patch Third Party Advisory
https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20200127-0004/ Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html Mailing List Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E Mailing List Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
History
Created Old Value New Value Data Type Notes
2022-05-10 07:06:21 Added to TrackCVE
2022-12-04 08:55:35 2020-01-03T04:15Z 2020-01-03T04:15:12 CVE Published Date updated
2022-12-04 08:55:35 2022-10-29T02:34:00 CVE Modified Date updated
2022-12-04 08:55:35 Analyzed Vulnerability Status updated