peter bassill · operator
$ cve CVE-2018-14721 JSON

CVE-2018-14721

10.0
CRITICAL · CVSS 3.0 · EPSS 10.5% (pctl 96)

Patch early

EPSS 10.5% — above the 10% action threshold.

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

Scoring

CVSS10.0 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS10.46% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploitnone known
Published2019-01-02
Last modified2026-06-17

Affected (12)

VendorProduct
debiandebian linux
fasterxmljackson-databind
oraclebanking platform
oraclecommunications billing and revenue management
oracleenterprise manager for virtualization
oraclefinancial services analytical applications infrastructure
oraclejdeveloper
oracleprimavera unifier
oracleretail merchandising system
oraclewebcenter portal
redhatjboss enterprise application platform
redhatopenshift container platform

References

→ the Explorer  ·  watch your stack  ·  NVD