CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-16335

CVSS 9.8v3.1pub. 2019-09-15upd. 2024-11-21

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Debian

    OS
    Debian
    10.08.09.0
  • Fasterxml Jackson Databind

    APP
    Fasterxml
    2.0.0 – 2.6.7.3 (excl.)2.7.0 – 2.8.11.5 (excl.)2.9.0 – 2.9.10 (excl.)
  • Fedora Project Fedora

    OS
    Fedoraproject
    3031
  • Netapp Oncommand Api Services

    APP
    Netapp
    all versions
  • Netapp Oncommand Workflow Automation

    APP
    Netapp
    all versions
  • Netapp Steelstore Cloud Integrated Storage

    APP
    Netapp
    all versions
  • Oracle Banking Platform

    APP
    Oracle
    2.4.02.4.12.5.02.6.02.6.12.7.02.7.1
  • Oracle Customer Management And Segmentation Foundation

    APP
    Oracle
    18.0
  • Oracle Financial Services Analytical Applications Infrastructure

    APP
    Oracle
    8.0.2 – 8.0.8
  • Oracle Global Lifecycle Management Opatch

    APP
    Oracle
    12.2.0.1.0 – 12.2.0.1.19 (excl.)13.9.4.0.0 – 13.9.4.2.1 (excl.)< 11.2.0.3.23
  • Oracle Goldengate Application Adapters

    APP
    Oracle
    19.1.0.0.0
  • Oracle Goldengate Stream Analytics

    APP
    Oracle
    < 19.1.0.0.1
  • Oracle Primavera Gateway

    APP
    Oracle
    15.216.116.218.8.017.7 – 17.12
  • Oracle Retail Customer Management And Segmentation Foundation

    APP
    Oracle
    17.0
  • Oracle Retail Xstore Point Of Service

    APP
    Oracle
    15.016.017.018.07.1
  • Oracle Weblogic Server

    APP
    Oracle
    12.2.1.3.0
  • Red Hat Enterprise Linux

    OS
    Redhat
    6.07.08.0
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.27.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXEDeserialization
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki