peter bassill · operator
$ cve CVE-2019-16942 JSON

CVE-2019-16942

9.8
CRITICAL · CVSS 3.1 · EPSS 5.7% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.73% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-10-01
Last modified2026-06-17

Affected (29)

VendorProduct
debiandebian linux
fasterxmljackson-databind
fedoraprojectfedora
netappactive iq unified manager
netapponcommand api services
netapponcommand workflow automation
netappservice level manager
netappsteelstore cloud integrated storage
oraclebanking platform
oraclecommunications billing and revenue management
oraclecommunications calendar server
oraclecommunications cloud native core network slice selection function
oraclecommunications evolved communications application server
oracledatabase server
oracleglobal lifecycle management nextgen oui framework
oraclegoldengate application adapters
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oracleprimavera gateway
oracleprimavera unifier
oracleretail merchandising system
oracleretail sales audit
oraclesiebel engineering - installer \& deployment
oraclesiebel ui framework
oraclewebcenter portal
oraclewebcenter sites
oracleweblogic server
redhatenterprise linux
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD