peter bassill · operator
$ cve CVE-2019-14540 JSON

CVE-2019-14540

9.8
CRITICAL · CVSS 3.1 · EPSS 10.8% (pctl 96)

Patch early

EPSS 10.8% — above the 10% action threshold.

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.76% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-09-15
Last modified2026-06-17

Affected (20)

VendorProduct
debiandebian linux
fasterxmljackson-databind
fedoraprojectfedora
netapponcommand api services
netapponcommand workflow automation
netappsteelstore cloud integrated storage
oraclebanking platform
oraclecustomer management and segmentation foundation
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatch
oraclegoldengate application adapters
oraclegoldengate stream analytics
oraclemysql
oracleprimavera gateway
oracleprimavera unifier
oracleretail customer management and segmentation foundation
oracleretail xstore point of service
oracleweblogic server
redhatenterprise linux
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD