CVE-2017-15095
9.8
CRITICAL · CVSS 3.1 · EPSS 8.4% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.36% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-184 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-02-06 |
| Last modified | 2026-06-17 |
Affected (25)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fasterxml | jackson-databind |
| netapp | oncommand balance |
| netapp | oncommand performance manager |
| netapp | oncommand shift |
| netapp | snapcenter |
| oracle | banking platform |
| oracle | clusterware |
| oracle | communications billing and revenue management |
| oracle | communications diameter signaling router |
| oracle | communications instant messaging server |
| oracle | database server |
| oracle | enterprise manager for virtualization |
| oracle | financial services analytical applications infrastructure |
| oracle | global lifecycle management opatchauto |
| oracle | identity manager |
| oracle | jd edwards enterpriseone tools |
| oracle | primavera unifier |
| oracle | utilities advanced spatial and operational analytics |
| oracle | webcenter portal |
| redhat | enterprise linux |
| redhat | jboss enterprise application platform |
| redhat | openshift container platform |
| redhat | satellite |
| redhat | satellite capsule |
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/103880
- http://www.securitytracker.com/id/1039769
- https://access.redhat.com/errata/RHSA-2017:3189
- https://access.redhat.com/errata/RHSA-2017:3190
- https://access.redhat.com/errata/RHSA-2018:0342
- https://access.redhat.com/errata/RHSA-2018:0478
- https://access.redhat.com/errata/RHSA-2018:0479
- https://access.redhat.com/errata/RHSA-2018:0480
- https://access.redhat.com/errata/RHSA-2018:0481
- https://access.redhat.com/errata/RHSA-2018:0576
- https://access.redhat.com/errata/RHSA-2018:0577
- https://access.redhat.com/errata/RHSA-2018:1447
- https://access.redhat.com/errata/RHSA-2018:1448
- https://access.redhat.com/errata/RHSA-2018:1449
- https://access.redhat.com/errata/RHSA-2018:1450
- https://access.redhat.com/errata/RHSA-2018:1451
- https://access.redhat.com/errata/RHSA-2018:2927
→ the Explorer · watch your stack · NVD