peter bassill · operator
$ cve CVE-2017-15095 JSON

CVE-2017-15095

9.8
CRITICAL · CVSS 3.1 · EPSS 8.4% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.36% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-184
On CISA KEVno
Public exploitnone known
Published2018-02-06
Last modified2026-06-17

Affected (25)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netapponcommand balance
netapponcommand performance manager
netapponcommand shift
netappsnapcenter
oraclebanking platform
oracleclusterware
oraclecommunications billing and revenue management
oraclecommunications diameter signaling router
oraclecommunications instant messaging server
oracledatabase server
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatchauto
oracleidentity manager
oraclejd edwards enterpriseone tools
oracleprimavera unifier
oracleutilities advanced spatial and operational analytics
oraclewebcenter portal
redhatenterprise linux
redhatjboss enterprise application platform
redhatopenshift container platform
redhatsatellite
redhatsatellite capsule

References

→ the Explorer  ·  watch your stack  ·  NVD