peter bassill · operator
$ cve CVE-2019-17531 JSON

CVE-2019-17531

9.8
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.37% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-10-12
Last modified2026-06-17

Affected (23)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netapponcommand workflow automation
netappsteelstore cloud integrated storage
oraclebanking platform
oraclecommunications billing and revenue management
oraclecommunications calendar server
oraclecommunications cloud native core network slice selection function
oraclecommunications evolved communications application server
oracleglobal lifecycle management nextgen oui framework
oraclegoldengate application adapters
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oracleprimavera gateway
oracleretail merchandising system
oracleretail sales audit
oraclesiebel engineering - installer \& deployment
oracletrace file analyzer
oraclewebcenter portal
oraclewebcenter sites
oracleweblogic server
redhatenterprise linux server
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD