peter bassill · operator
$ cve CVE-2017-7525 JSON

CVE-2017-7525

9.8
CRITICAL · CVSS 3.1 · EPSS 37.7% (pctl 99)

Patch early

EPSS 37.7% — above the 10% action threshold.

Description

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS37.72% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-184
On CISA KEVno
Public exploitnone known
Published2018-02-06
Last modified2026-06-17

Affected (22)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netapponcommand balance
netapponcommand performance manager
netapponcommand shift
netappsnapcenter
oraclebanking platform
oraclecommunications billing and revenue management
oraclecommunications communications policy management
oraclecommunications diameter signaling route
oraclecommunications instant messaging server
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatchauto
oracleprimavera unifier
oracleutilities advanced spatial and operational analytics
oraclewebcenter portal
redhatenterprise linux server
redhatjboss enterprise application platform
redhatopenshift container platform
redhatvirtualization
redhatvirtualization host

References

→ the Explorer  ·  watch your stack  ·  NVD