peter bassill · operator
$ cve CVE-2018-14720 JSON

CVE-2018-14720

9.8
CRITICAL · CVSS 3.0 · EPSS 7.5% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.52% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-01-02
Last modified2026-06-17

Affected (12)

VendorProduct
debiandebian linux
fasterxmljackson-databind
oraclebanking platform
oraclecommunications billing and revenue management
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oraclejdeveloper
oracleprimavera unifier
oracleretail merchandising system
oraclewebcenter portal
redhatjboss enterprise application platform
redhatopenshift container platform

References

→ the Explorer  ·  watch your stack  ·  NVD