CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2019-14379: jackson-databind from 2.0.0 (inclusive), before 2.6.7.3 (exclusive), from 2.7.0 (inclusive), before 2.7.9.6…

CVE-2019-14379. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.08111 (percentile 0.94695), scored 2026-10-08.

Affected technology

jackson-databind · from 2.0.0 (inclusive), before 2.6.7.3 (exclusive)
fasterxml

jackson-databind · from 2.7.0 (inclusive), before 2.7.9.6 (exclusive)
fasterxml

jackson-databind · from 2.8.0 (inclusive), before 2.8.11.4 (exclusive)
fasterxml

jackson-databind · from 2.9.0 (inclusive), before 2.9.9.2 (exclusive)
fasterxml

debian linux · 8.0
debian

active iq unified manager · from 7.3 (inclusive)
netapp

active iq unified manager · from 9.5 (inclusive)
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

service level manager · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

fedora · 29
fedoraproject

fedora · 30
fedoraproject

fedora · 31
fedoraproject

jboss enterprise application platform · 7.2
redhat

jboss enterprise application platform · 7.3
redhat

openshift container platform · 4.1
redhat

single sign-on · 7.3
redhat

openshift container platform · 3.11
redhat

banking platform · 2.4.0
oracle

banking platform · 2.4.1
oracle

banking platform · 2.5.0
oracle

banking platform · 2.6.0
oracle

banking platform · 2.6.1
oracle

banking platform · 2.7.0
oracle

banking platform · 2.7.1
oracle

communications diameter signaling router · 8.0.0
oracle

communications diameter signaling router · 8.1
oracle

communications diameter signaling router · 8.2
oracle

communications diameter signaling router · 8.2.1
oracle

communications instant messaging server · 10.0.1.3.0
oracle

financial services analytical applications infrastructure · from 8.0.2 (inclusive), through 8.0.8 (inclusive)
oracle

goldengate stream analytics · before 19.1.0.0.1 (exclusive)
oracle

jd edwards enterpriseone orchestrator · 9.2
oracle

jd edwards enterpriseone tools · 9.2
oracle

primavera gateway · 15.2
oracle

primavera gateway · 16.2
oracle

primavera gateway · 17.12
oracle

primavera gateway · 18.8.0
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 16.1
oracle

primavera unifier · 16.2
oracle

primavera unifier · 18.8
oracle

retail customer management and segmentation foundation · 17.0
oracle

retail xstore point of service · 7.1
oracle

retail xstore point of service · 15.0
oracle

retail xstore point of service · 16.0
oracle

retail xstore point of service · 17.0
oracle

retail xstore point of service · 18.0
oracle

siebel engineering - installer & deployment · through 19.8 (inclusive)
oracle

siebel ui framework · through 19.10 (inclusive)
oracle

xcode · before 13.3 (exclusive)
apple

n/a · n/a
Vendor not specified by the source

Description’s affected range: before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup)

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-1321
CCR priority
41.2 /100 (P3)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.08111 · percentile 0.94695 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2019-14379.html