peter bassill · operator
$ cve CVE-2019-17267 JSON

CVE-2019-17267

9.8
CRITICAL · CVSS 3.1 · EPSS 4.6% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.63% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-10-07
Last modified2026-10-07

Affected (13)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netappactive iq unified manager
netapponcommand api services
netapponcommand workflow automation
netappservice level manager
netappsteelstore cloud integrated storage
oraclecustomer management and segmentation foundation
oraclegoldengate application adapters
oracleretail customer management and segmentation foundation
oracleweblogic server
redhatenterprise linux
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD