SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7525

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the…

CRITICAL 9.8EPSS 37.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 37.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
37.72% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-184, CWE-502
Affected
fasterxml/jackson-databind · debian/debian linux · netapp/oncommand balance · netapp/oncommand performance manager · netapp/oncommand shift · netapp/snapcenter · redhat/openshift container platform · redhat/virtualization · redhat/virtualization host · redhat/jboss enterprise application platform · oracle/banking platform · oracle/communications billing and revenue management · oracle/communications communications policy management · oracle/communications diameter signaling route · oracle/communications instant messaging server · oracle/enterprise manager for virtualization · oracle/financial services analytical applications infrastructure · oracle/global lifecycle management opatchauto · oracle/primavera unifier · oracle/utilities advanced spatial and operational analytics · +1 more
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.