peter bassill · operator
$ cve CVE-2019-20330 JSON

CVE-2019-20330

9.8
CRITICAL · CVSS 3.1 · EPSS 8.6% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.64% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-01-03
Last modified2026-06-17

Affected (30)

VendorProduct
debiandebian linux
fasterxmljackson-databind
netappactive iq unified manager
netapponcommand api services
netappservice level manager
netappsnapcenter
netappsteelstore cloud integrated storage
oraclebanking platform
oraclecommunications billing and revenue management
oraclecommunications cloud native core network slice selection function
oraclecommunications contacts server
oraclecommunications evolved communications application server
oraclecommunications instant messaging server
oraclecommunications network charging and control
oraclecustomer management and segmentation foundation
oracleenterprise manager base platform
oracleglobal lifecycle management opatch
oraclegoldengate application adapters
oraclegoldengate stream analytics
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oracleprimavera unifier
oracleretail merchandising system
oracleretail sales audit
oracleretail xstore point of service
oraclesiebel engineering - installer \& deployment
oraclesiebel ui framework
oracletrace file analyzer
oraclewebcenter portal
oracleweblogic server

References

→ the Explorer  ·  watch your stack  ·  NVD