7.5 CVE-2020-36518
Exploit
jackson-databind vor 2.13.0 ermöglicht eine Java StackOverflow Exception und Denial of Service über eine große Tiefe von verschachtelten Objekten.
https://nvd.nist.gov/vuln/detail/CVE-2020-36518
Kategorien
CWE-787 : Außerhalb des Bereichs Schreiben
Typischerweise kann dies zu einer Beschädigung von Daten, einem Absturz oder der Ausführung von Code führen. Die Software ändert möglicherweise einen Index oder führt eine Zeigerarithmetik durch, die auf eine Speicherstelle verweist, die außerhalb der Grenzen des Puffers liegt. Ein anschließender Schreibvorgang führt dann zu undefinierten oder unerwarteten Ergebnissen.
Referenzen
CONFIRM
https://security.netapp.com/advisory/ntap-20220506-0004/ Third Party Advisory |
DEBIAN
DSA-5283 Third Party Advisory |
MISC
https://github.com/FasterXML/jackson-databind/issues/2816 Issue Tracking Third Party Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory |
N/A
N/A Third Party Advisory |
_MLIST Exploit
[debian-lts-announce] 20220502 [SECURITY] [DLA 2990-1] jackson-databind security update Exploit Mailing List Third Party Advisory |
[debian-lts-announce] 20221127 [SECURITY] [DLA 3207-1] jackson-databind security update Mailing List Third Party Advisory |
CPE
cpe | start | ende |
---|---|---|
Configuration 1 | ||
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | < 2.12.6.1 | |
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | >= 2.13.0 | < 2.13.2.1 |
Configuration 2 | ||
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:commerce_platform:11.3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:utilities_framework:4.3.0.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:utilities_framework:4.3.0.6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* | >= 17.12.0 | <= 17.12.11 |
cpe:2.3:a:oracle:utilities_framework:4.4.0.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:commerce_platform:11.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.7:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:* | < 23.1 | |
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.7.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_billing_and_revenue_management:*:*:*:*:*:*:*:* | >= 12.0.0.4.0 | <= 12.0.0.6.0 |
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:utilities_framework:4.4.0.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:*:*:*:*:*:*:*:* | < 13.9.4.2.2 | |
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_enterprise_case_management:*:*:*:*:*:*:*:* | >= 8.1.1.0 | <= 8.1.2.1 |
cpe:2.3:a:oracle:retail_sales_audit:15.0.3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:health_sciences_empirica_signal:9.1.0.5.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:spatial_studio:*:*:*:*:*:*:*:* | < 20.1.0 | |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* | >= 20.12.0 | <= 20.12.18 |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* | >= 19.12.0 | <= 19.12.13 |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* | >= 21.12.0 | <= 21.12.1 |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* | >= 18.8.0 | <= 18.8.14 |
cpe:2.3:a:oracle:primavera_unifier:18.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.7.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:* | >= 8.1.1.0 | <= 8.1.2.1 |
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* | >= 18.8.0.0 | <= 18.8.25.4 |
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* | >= 19.12.0 | <= 19.12.19.0 |
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* | >= 17.0 | <= 17.12 |
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* | >= 8.0.7 | <= 8.1.0.0 |
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* | >= 20.12.0.0 | <= 21.12.4.0 |
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* | >= 17.12.0.0 | <= 17.12.20.4 |
cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:22.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:* | < 12.2.0.1.30 | |
cpe:2.3:a:oracle:graph_server_and_client:*:*:*:*:*:*:*:* | < 22.2.0 | |
Configuration 3 | ||
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
Configuration 4 | ||
cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:* |
Exploits
Exploit-db.com
id | beschreibung | datum | |
---|---|---|---|
Keine bekannten Exploits |
Andere (github, ...)
Url |
---|
[debian-lts-announce] 20220502 [SECURITY] [DLA 2990-1] jackson-databind security update |
CAPEC
id | beschreibung | schweregrad |
---|---|---|
Kein Eintrag |
Sherlock® flash
Machen Sie mit wenigen Klicks ein Foto von Ihrem Computernetzwerk !
Mit der Sherlock® flash Audit-Lösung können Sie ein Audit durchführen, um die Sicherheit Ihres Computerbestands zu erhöhen. Scannen Sie Ihre physischen und virtuellen Geräte auf Schwachstellen. Planung von Patches nach Priorität und verfügbarer Zeit. Detaillierte und intuitive Berichte.
