CVE-2020-11619

Published Apr 7, 2020

Last updated 3 days ago

Overview

Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Source
cve@mitre.org
NVD status
Analyzed
Products
jackson-databind, debian_linux, active_iq_unified_manager, steelstore_cloud_integrated_storage, agile_plm, banking_platform, communications_calendar_server, communications_contacts_server, communications_diameter_signaling_router, communications_evolved_communications_application_server, communications_instant_messaging_server, communications_network_charging_and_control, enterprise_manager_base_platform, global_lifecycle_management_opatch, jd_edwards_enterpriseone_orchestrator, jd_edwards_enterpriseone_tools, primavera_unifier, retail_merchandising_system, retail_sales_audit, retail_xstore_point_of_service, weblogic_server

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.4
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending

Configurations