peter bassill · operator
$ cve CVE-2019-16335 JSON

CVE-2019-16335

9.8
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.96% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-09-15
Last modified2026-06-17

Affected (18)

VendorProduct
debiandebian linux
fasterxmljackson-databind
fedoraprojectfedora
netapponcommand api services
netapponcommand workflow automation
netappsteelstore cloud integrated storage
oraclebanking platform
oraclecustomer management and segmentation foundation
oraclefinancial services analytical applications infrastructure
oracleglobal lifecycle management opatch
oraclegoldengate application adapters
oraclegoldengate stream analytics
oracleprimavera gateway
oracleretail customer management and segmentation foundation
oracleretail xstore point of service
oracleweblogic server
redhatenterprise linux
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD