CVE-2018-1000873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/12/2018
Last modified:
07/11/2023

Description

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fasterxml:jackson-modules-java8:*:*:*:*:*:*:*:* 2.9.8 (excluding)
cpe:2.3:a:oracle:clusterware:12.1.0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 11.2.0.3.23 (excluding)
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 12.2.0.1.0 (including) 12.2.0.1.19 (excluding)
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* 13.9.4.0.0 (including) 13.9.4.2.1 (excluding)
cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:* 19.3.12 (excluding)
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:* 7.3 (including)
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* 7.3 (including)
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* 9.5 (including)