VulnerabilityModified
CVE-2019-14379
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CRITICAL 9.8EPSS 8.11%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.11% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- fasterxml/jackson-databind · debian/debian linux · netapp/active iq unified manager · netapp/oncommand workflow automation · netapp/service level manager · netapp/snapcenter · fedoraproject/fedora · redhat/jboss enterprise application platform · redhat/openshift container platform · redhat/single sign-on · oracle/banking platform · oracle/communications diameter signaling router · oracle/communications instant messaging server · oracle/financial services analytical applications infrastructure · oracle/goldengate stream analytics · oracle/jd edwards enterpriseone orchestrator · oracle/jd edwards enterpriseone tools · oracle/primavera gateway · oracle/primavera unifier · oracle/retail customer management and segmentation foundation · +4 more
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2022/Mar/23Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2743Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2935Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2937Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2938Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2998Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3044Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3046Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3050Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3200Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3292Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3297Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2Patch, Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2387Issue Tracking, Patch, Third Party Advisory
- https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815%40%3Cissues.iceberg.apache.org%3E
- https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.