Get real-time updates on Telegram
CVE-2019-14379: jackson-databind from 2.0.0 (inclusive), before 2.6.7.3 (exclusive), from 2.7.0 (inclusive), before 2.7.9.6…
CVE-2019-14379. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.08111 (percentile 0.94695), scored 2026-10-08.
Affected technology
jackson-databind · from 2.0.0 (inclusive), before 2.6.7.3 (exclusive)
fasterxml
jackson-databind · from 2.7.0 (inclusive), before 2.7.9.6 (exclusive)
fasterxml
jackson-databind · from 2.8.0 (inclusive), before 2.8.11.4 (exclusive)
fasterxml
jackson-databind · from 2.9.0 (inclusive), before 2.9.9.2 (exclusive)
fasterxml
debian linux · 8.0
debian
active iq unified manager · from 7.3 (inclusive)
netapp
active iq unified manager · from 9.5 (inclusive)
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
service level manager · Version not applicable in the source CPE
netapp
snapcenter · Version not applicable in the source CPE
netapp
fedora · 29
fedoraproject
fedora · 30
fedoraproject
fedora · 31
fedoraproject
jboss enterprise application platform · 7.2
redhat
jboss enterprise application platform · 7.3
redhat
openshift container platform · 4.1
redhat
single sign-on · 7.3
redhat
openshift container platform · 3.11
redhat
banking platform · 2.4.0
oracle
banking platform · 2.4.1
oracle
banking platform · 2.5.0
oracle
banking platform · 2.6.0
oracle
banking platform · 2.6.1
oracle
banking platform · 2.7.0
oracle
banking platform · 2.7.1
oracle
communications diameter signaling router · 8.0.0
oracle
communications diameter signaling router · 8.1
oracle
communications diameter signaling router · 8.2
oracle
communications diameter signaling router · 8.2.1
oracle
communications instant messaging server · 10.0.1.3.0
oracle
financial services analytical applications infrastructure · from 8.0.2 (inclusive), through 8.0.8 (inclusive)
oracle
goldengate stream analytics · before 19.1.0.0.1 (exclusive)
oracle
jd edwards enterpriseone orchestrator · 9.2
oracle
jd edwards enterpriseone tools · 9.2
oracle
primavera gateway · 15.2
oracle
primavera gateway · 16.2
oracle
primavera gateway · 17.12
oracle
primavera gateway · 18.8.0
oracle
primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle
primavera unifier · 16.1
oracle
primavera unifier · 16.2
oracle
primavera unifier · 18.8
oracle
retail customer management and segmentation foundation · 17.0
oracle
retail xstore point of service · 7.1
oracle
retail xstore point of service · 15.0
oracle
retail xstore point of service · 16.0
oracle
retail xstore point of service · 17.0
oracle
retail xstore point of service · 18.0
oracle
siebel engineering - installer & deployment · through 19.8 (inclusive)
oracle
siebel ui framework · through 19.10 (inclusive)
oracle
xcode · before 13.3 (exclusive)
apple
n/a · n/a
Vendor not specified by the source
Description’s affected range: before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup)
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-1321
- CCR priority
- 41.2 /100 (P3)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.08111 · percentile 0.94695 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2019-14379.html