peter bassill · operator
$ cve CVE-2019-14379 JSON

CVE-2019-14379

9.8
CRITICAL · CVSS 3.1 · EPSS 8.1% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.11% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-1321
On CISA KEVno
Public exploitnone known
Published2019-07-29
Last modified2026-06-17

Affected (25)

VendorProduct
applexcode
debiandebian linux
fasterxmljackson-databind
fedoraprojectfedora
netappactive iq unified manager
netapponcommand workflow automation
netappservice level manager
netappsnapcenter
oraclebanking platform
oraclecommunications diameter signaling router
oraclecommunications instant messaging server
oraclefinancial services analytical applications infrastructure
oraclegoldengate stream analytics
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oracleprimavera gateway
oracleprimavera unifier
oracleretail customer management and segmentation foundation
oracleretail xstore point of service
oraclesiebel engineering - installer \& deployment
oraclesiebel ui framework
redhatenterprise linux
redhatjboss enterprise application platform
redhatopenshift container platform
redhatsingle sign-on

References

→ the Explorer  ·  watch your stack  ·  NVD