peter bassill · operator
$ cve CVE-2018-14718 JSON

CVE-2018-14718

9.8
CRITICAL · CVSS 3.1 · EPSS 12.7% (pctl 96)

Patch early

EPSS 12.7% — above the 10% action threshold.

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.68% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-01-02
Last modified2026-06-17

Affected (26)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netapponcommand workflow automation
netappsnapcenter
netappsteelstore cloud integrated storage
oraclebanking platform
oraclebusiness process management suite
oraclecommunications billing and revenue management
oraclecommunications instant messaging server
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatch
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oraclejdeveloper
oraclenosql database
oracleprimavera p6 enterprise project portfolio management
oracleprimavera unifier
oracleretail customer management and segmentation foundation
oracleretail merchandising system
oracleretail workforce management software
oraclesiebel engineering - installer \& deployment
oraclesiebel ui framework
oraclewebcenter portal
redhatenterprise linux
redhatopenshift container platform

References

→ the Explorer  ·  watch your stack  ·  NVD