CVE-2018-7489

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2018
Last modified:
07/11/2023

Description

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.7.9.3 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.11.1 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.5 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4.19:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools