A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDebian
OSDebian8.0Fasterxml Jackson Databind
APPFasterxml2.9.0 – 2.9.10 (excl.)2.0.0 – 2.8.11.5 (excl.)Netapp Active Iq Unified Manager
APPNetapp≥ 9.5≥ 7.3Netapp Oncommand Api Services
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Service Level Manager
APPNetappall versionsNetapp Steelstore Cloud Integrated Storage
APPNetappall versionsOracle Customer Management And Segmentation Foundation
APPOracle< 18.0Oracle Goldengate Application Adapters
APPOracle19.1.0.0.0Oracle Retail Customer Management And Segmentation Foundation
APPOracle17.0Oracle Weblogic Server
APPOracle12.2.1.3.0Red Hat Enterprise Linux
OSRedhat6.07.08.0Red Hat Jboss Enterprise Application Platform
APPRedhat7.27.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References
Related vulnerabilities
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki