{ "containers": { "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "descriptions": [ { "lang": "en", "value": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy)." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2021-10-20T10:38:43.000Z", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "name": "[debian-lts-announce] 20200417 [SECURITY] [DLA 2179-1] jackson-databind security update", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://security.netapp.com/advisory/ntap-20200403-0002/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/FasterXML/jackson-databind/issues/2662" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.oracle.com/security-alerts/cpujan2021.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-10968", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy)." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "[debian-lts-announce] 20200417 [SECURITY] [DLA 2179-1] jackson-databind security update", "refsource": "MLIST", "url": "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html" }, { "name": "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", "refsource": "MISC", "url": "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062" }, { "name": "https://www.oracle.com/security-alerts/cpujul2020.html", "refsource": "MISC", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, { "name": "https://security.netapp.com/advisory/ntap-20200403-0002/", "refsource": "CONFIRM", "url": "https://security.netapp.com/advisory/ntap-20200403-0002/" }, { "name": "https://github.com/FasterXML/jackson-databind/issues/2662", "refsource": "MISC", "url": "https://github.com/FasterXML/jackson-databind/issues/2662" }, { "name": "https://www.oracle.com/security-alerts/cpuoct2020.html", "refsource": "MISC", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" }, { "name": "https://www.oracle.com/security-alerts/cpujan2021.html", "refsource": "MISC", "url": "https://www.oracle.com/security-alerts/cpujan2021.html" }, { "name": "https://www.oracle.com/security-alerts/cpuoct2021.html", "refsource": "MISC", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" } ] } } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-502", "lang": "en", "description": "CWE-502 Deserialization of Untrusted Data" } ] } ], "affected": [ { "vendor": "debian", "product": "debian_linux", "cpes": [ "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0", "status": "affected" } ] }, { "vendor": "netapp", "product": "steelstore_cloud_integrated_storage", "cpes": [ "cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "*", "status": "affected" } ] }, { "vendor": "oracle", "product": "agile_plm", "cpes": [ "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "9.3.6", "status": "affected" } ] }, { "vendor": "oracle", "product": "autovue_for_agile_product_lifecycle_management", "cpes": [ "cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "21.0.2", "status": "affected" } ] }, { "vendor": "oracle", "product": "banking_digital_experience", "cpes": [ "cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "18.1", "status": "affected", "lessThanOrEqual": "18.3", "versionType": "custom" }, { "version": "19.1", "status": "affected", "lessThanOrEqual": "19.2", "versionType": "custom" }, { "version": "20.1", "status": "affected" }, { "version": "2.4.0", "status": "affected", "lessThanOrEqual": "2.9.0", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "communications_calendar_server", "cpes": [ "cpe:2.3:a:oracle:communications_calendar_server:8.0.0.4.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.0.4.0", "status": "affected", "lessThanOrEqual": "8.0.0.5.0", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "communications_diameter_signaling_router", "cpes": [ "cpe:2.3:a:oracle:communications_diameter_signaling_router:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.0", "status": "affected", "lessThanOrEqual": "8.2.2", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "communications_element_manager", "cpes": [ "cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.2.0", "status": "affected", "lessThanOrEqual": "8.2.2", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "communications_evolved_communications_application_server", "cpes": [ "cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "7.1", "status": "affected" } ] }, { "vendor": "oracle", "product": "communications_instant_messaging_server", "cpes": [ "cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "10.0.1.4.0", "status": "affected" } ] }, { "vendor": "oracle", "product": "communications_network_charging_and_control", "cpes": [ "cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "6.0.1", "status": "affected" } ] }, { "vendor": "oracle", "product": "communications_network_charging_and_control", "cpes": [ "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "12.0.0", "status": "affected", "lessThanOrEqual": "12.0.3", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "communications_session_route_manager", "cpes": [ "cpe:2.3:a:oracle:communications_session_route_manager:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.2.0", "status": "affected", "lessThanOrEqual": "8.2.2", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "enterprise_manager_base_platform", "cpes": [ "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "13.3.0.0", "status": "affected", "lessThanOrEqual": "13.4.0.0", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "financial_services_analytical_applications_infrastructure", "cpes": [ "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.6", "status": "affected", "lessThanOrEqual": "8.1.0", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "financial_services_institutional_performance_analytics", "cpes": [ "cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.6", "status": "affected" }, { "version": "8.0.7", "status": "affected" }, { "version": "8.1.0", "status": "affected" } ] }, { "vendor": "oracle", "product": "financial_services_price_creation_and_discovery", "cpes": [ "cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.6", "status": "affected", "lessThanOrEqual": "8.0.7", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "financial_services_retail_customer_analytics", "cpes": [ "cpe:2.3:a:oracle:financial_services_retail_customer_analytics:8.0.6:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "8.0.6", "status": "affected" } ] }, { "vendor": "oracle", "product": "global_lifecycle_management_opatch", "cpes": [ "cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "12.2.0.1.20", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "insurance_policy_administration_j2ee", "cpes": [ "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "11.0.2.25", "status": "affected", "lessThan": "11.1.0.15", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "jd_edwards_enterpriseone_orchestrator", "cpes": [ "cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "9.2.4.2", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "primavera_unifier", "cpes": [ "cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "16.1", "status": "affected" }, { "version": "16.2", "status": "affected" }, { "version": "17.7", "status": "affected", "lessThanOrEqual": "17.12", "versionType": "custom" }, { "version": "18.8", "status": "affected" }, { "version": "19.12", "status": "affected" } ] }, { "vendor": "oracle", "product": "retail_merchandising_system", "cpes": [ "cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "15.0", "status": "affected" } ] }, { "vendor": "oracle", "product": "retail_sales_audit", "cpes": [ "cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "14.1", "status": "affected" } ] }, { "vendor": "oracle", "product": "retail_service_backbone", "cpes": [ "cpe:2.3:a:oracle:retail_service_backbone:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "14.1", "status": "affected" }, { "version": "15.0", "status": "affected" }, { "version": "16.0", "status": "affected" } ] }, { "vendor": "oracle", "product": "retail_xstore_point_of_service", "cpes": [ "cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "15.0", "status": "affected", "lessThanOrEqual": "19.0", "versionType": "custom" } ] }, { "vendor": "oracle", "product": "weblogic_server", "cpes": [ "cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "12.2.1.3.0", "status": "affected", "lessThanOrEqual": "12.2.1.4.0", "versionType": "custom" } ] }, { "vendor": "fasterxml", "product": "jackson-databind", "cpes": [ "cpe:2.3:a:fasterxml:jackson-databind:2.0.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "2.0.0", "status": "affected", "lessThan": "2.9.10.4", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2024-05-25T04:00:46.867668Z", "id": "CVE-2020-10968", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-04T19:57:31.283Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T11:21:14.276Z" }, "title": "CVE Program Container", "references": [ { "name": "[debian-lts-announce] 20200417 [SECURITY] [DLA 2179-1] jackson-databind security update", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://security.netapp.com/advisory/ntap-20200403-0002/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/FasterXML/jackson-databind/issues/2662" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.oracle.com/security-alerts/cpujan2021.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" } ] } ] }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2020-10968", "datePublished": "2020-03-26T12:43:45.000Z", "dateReserved": "2020-03-26T00:00:00.000Z", "dateUpdated": "2024-08-04T11:21:14.276Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }