A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDebian
OSDebian10.08.09.0Fasterxml Jackson Databind
APPFasterxml2.0.0 – 2.6.7.3 (excl.)2.7.0 – 2.8.11.5 (excl.)2.9.0 – 2.9.10 (excl.)Fedora Project Fedora
OSFedoraproject3031Netapp Oncommand Api Services
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Steelstore Cloud Integrated Storage
APPNetappall versionsOracle Banking Platform
APPOracle2.4.02.4.12.5.02.6.02.6.12.7.02.7.1Oracle Customer Management And Segmentation Foundation
APPOracle18.0Oracle Financial Services Analytical Applications Infrastructure
APPOracle8.0.2 – 8.0.8Oracle Global Lifecycle Management Opatch
APPOracle12.2.0.1.0 – 12.2.0.1.19 (excl.)13.9.4.0.0 – 13.9.4.2.1 (excl.)< 11.2.0.3.23Oracle Goldengate Application Adapters
APPOracle19.1.0.0.0Oracle Goldengate Stream Analytics
APPOracle< 19.1.0.0.1Oracle Primavera Gateway
APPOracle15.216.116.218.8.017.7 – 17.12Oracle Retail Customer Management And Segmentation Foundation
APPOracle17.0Oracle Retail Xstore Point Of Service
APPOracle15.016.017.018.07.1Oracle Weblogic Server
APPOracle12.2.1.3.0Red Hat Enterprise Linux
OSRedhat6.07.08.0Red Hat Jboss Enterprise Application Platform
APPRedhat7.27.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXEDeserialization
CWE
References
Related vulnerabilities
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki