CVE-2019-14379
9.8
CRITICAL · CVSS 3.1 · EPSS 8.1% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.11% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-1321 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-29 |
| Last modified | 2026-06-17 |
Affected (25)
| Vendor | Product |
|---|---|
| apple | xcode |
| debian | debian linux |
| fasterxml | jackson-databind |
| fedoraproject | fedora |
| netapp | active iq unified manager |
| netapp | oncommand workflow automation |
| netapp | service level manager |
| netapp | snapcenter |
| oracle | banking platform |
| oracle | communications diameter signaling router |
| oracle | communications instant messaging server |
| oracle | financial services analytical applications infrastructure |
| oracle | goldengate stream analytics |
| oracle | jd edwards enterpriseone orchestrator |
| oracle | jd edwards enterpriseone tools |
| oracle | primavera gateway |
| oracle | primavera unifier |
| oracle | retail customer management and segmentation foundation |
| oracle | retail xstore point of service |
| oracle | siebel engineering - installer \& deployment |
| oracle | siebel ui framework |
| redhat | enterprise linux |
| redhat | jboss enterprise application platform |
| redhat | openshift container platform |
| redhat | single sign-on |
References
- http://seclists.org/fulldisclosure/2022/Mar/23
- https://access.redhat.com/errata/RHBA-2019:2824
- https://access.redhat.com/errata/RHSA-2019:2743
- https://access.redhat.com/errata/RHSA-2019:2858
- https://access.redhat.com/errata/RHSA-2019:2935
- https://access.redhat.com/errata/RHSA-2019:2936
- https://access.redhat.com/errata/RHSA-2019:2937
- https://access.redhat.com/errata/RHSA-2019:2938
- https://access.redhat.com/errata/RHSA-2019:2998
- https://access.redhat.com/errata/RHSA-2019:3044
- https://access.redhat.com/errata/RHSA-2019:3045
- https://access.redhat.com/errata/RHSA-2019:3046
- https://access.redhat.com/errata/RHSA-2019:3050
- https://access.redhat.com/errata/RHSA-2019:3149
- https://access.redhat.com/errata/RHSA-2019:3200
- https://access.redhat.com/errata/RHSA-2019:3292
- https://access.redhat.com/errata/RHSA-2019:3297
- https://access.redhat.com/errata/RHSA-2019:3901
- https://access.redhat.com/errata/RHSA-2020:0727
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2
→ the Explorer · watch your stack · NVD