CVE-2017-7525
9.8
CRITICAL · CVSS 3.1 · EPSS 37.7% (pctl 99)
Patch early
EPSS 37.7% — above the 10% action threshold.
Description
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 37.72% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-184 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-02-06 |
| Last modified | 2026-06-17 |
Affected (22)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fasterxml | jackson-databind |
| netapp | oncommand balance |
| netapp | oncommand performance manager |
| netapp | oncommand shift |
| netapp | snapcenter |
| oracle | banking platform |
| oracle | communications billing and revenue management |
| oracle | communications communications policy management |
| oracle | communications diameter signaling route |
| oracle | communications instant messaging server |
| oracle | enterprise manager for virtualization |
| oracle | financial services analytical applications infrastructure |
| oracle | global lifecycle management opatchauto |
| oracle | primavera unifier |
| oracle | utilities advanced spatial and operational analytics |
| oracle | webcenter portal |
| redhat | enterprise linux server |
| redhat | jboss enterprise application platform |
| redhat | openshift container platform |
| redhat | virtualization |
| redhat | virtualization host |
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/99623
- http://www.securitytracker.com/id/1039744
- http://www.securitytracker.com/id/1039947
- http://www.securitytracker.com/id/1040360
- https://access.redhat.com/errata/RHSA-2017:1834
- https://access.redhat.com/errata/RHSA-2017:1835
- https://access.redhat.com/errata/RHSA-2017:1836
- https://access.redhat.com/errata/RHSA-2017:1837
- https://access.redhat.com/errata/RHSA-2017:1839
- https://access.redhat.com/errata/RHSA-2017:1840
- https://access.redhat.com/errata/RHSA-2017:2477
- https://access.redhat.com/errata/RHSA-2017:2546
- https://access.redhat.com/errata/RHSA-2017:2547
- https://access.redhat.com/errata/RHSA-2017:2633
- https://access.redhat.com/errata/RHSA-2017:2635
- https://access.redhat.com/errata/RHSA-2017:2636
- https://access.redhat.com/errata/RHSA-2017:2637
→ the Explorer · watch your stack · NVD