peter bassill · operator
$ cve CVE-2018-14719 JSON

CVE-2018-14719

9.8
CRITICAL · CVSS 3.1 · EPSS 9.7% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.68% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-01-02
Last modified2026-06-17

Affected (21)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netapponcommand workflow automation
netappsnapcenter
netappsteelstore cloud integrated storage
oraclebanking platform
oraclebusiness process management suite
oracleclusterware
oraclecommunications billing and revenue management
oracledatabase server
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatch
oraclejdeveloper
oracleprimavera p6 enterprise project portfolio management
oracleprimavera unifier
oracleretail merchandising system
oracleretail workforce management software
oraclewebcenter portal
redhatenterprise linux
redhatopenshift container platform

References

→ the Explorer  ·  watch your stack  ·  NVD