Get real-time updates on Telegram
CVE-2019-16943: jackson-databind from 2.0.0 (inclusive), before 2.6.7.3 (exclusive), from 2.7.0 (inclusive), before 2.8.11.5…
CVE-2019-16943. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.04901 (percentile 0.91848), scored 2026-10-06.
Affected technology
jackson-databind · from 2.0.0 (inclusive), before 2.6.7.3 (exclusive)
fasterxml
jackson-databind · from 2.7.0 (inclusive), before 2.8.11.5 (exclusive)
fasterxml
jackson-databind · from 2.9.0 (inclusive), before 2.9.10.1 (exclusive)
fasterxml
debian linux · 8.0
debian
debian linux · 9.0
debian
debian linux · 10.0
debian
fedora · 30
fedoraproject
fedora · 31
fedoraproject
jboss enterprise application platform · 7.2
redhat
jboss enterprise application platform · 7.3
redhat
banking platform · 2.4.0
oracle
banking platform · 2.4.1
oracle
banking platform · 2.5.0
oracle
banking platform · 2.6.0
oracle
banking platform · 2.6.1
oracle
banking platform · 2.6.2
oracle
banking platform · 2.7.0
oracle
banking platform · 2.7.1
oracle
banking platform · 2.9.0
oracle
communications billing and revenue management · 7.5.0.23.0
oracle
communications billing and revenue management · 12.0.0.3.0
oracle
communications calendar server · 8.0.0.2.0
oracle
communications calendar server · 8.0.0.3.0
oracle
communications cloud native core network slice selection function · 1.2.1
oracle
communications evolved communications application server · 7.1
oracle
global lifecycle management nextgen oui framework · 12.2.1.3.0
oracle
global lifecycle management nextgen oui framework · 12.2.1.4.0
oracle
global lifecycle management nextgen oui framework · 13.9.4.2.2
oracle
goldengate application adapters · 19.1.0.0.0
oracle
jd edwards enterpriseone orchestrator · 9.2
oracle
jd edwards enterpriseone tools · 9.2
oracle
primavera gateway · from 17.7 (inclusive), through 17.12.6 (inclusive)
oracle
primavera gateway · from 18.8.0 (inclusive), through 18.8.8 (inclusive)
oracle
primavera gateway · 16.1
oracle
primavera gateway · 16.2
oracle
primavera gateway · 19.12.0
oracle
retail merchandising system · 15.0.3
oracle
retail merchandising system · 16.0.2
oracle
retail merchandising system · 16.0.3
oracle
retail sales audit · 14.1
oracle
siebel engineering - installer & deployment · through 2.20.5 (inclusive)
oracle
trace file analyzer · 12.2.0.1
oracle
trace file analyzer · 18c
oracle
trace file analyzer · 19c
oracle
webcenter portal · 12.2.1.3.0
oracle
webcenter portal · 12.2.1.4.0
oracle
webcenter sites · 12.2.1.3.0
oracle
webcenter sites · 12.2.1.4.0
oracle
weblogic server · 12.2.1.3.0
oracle
weblogic server · 12.2.1.4.0
oracle
active iq unified manager · from 7.3 (inclusive)
netapp
active iq unified manager · from 9.5 (inclusive)
netapp
oncommand api services · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
service level manager · Version not applicable in the source CPE
netapp
steelstore cloud integrated storage · Version not applicable in the source CPE
netapp
n/a · n/a
Vendor not specified by the source
Description’s affected range: through 2.9.10
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source says when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-502
- CCR priority
- 40.4 /100 (P3)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.04901 · percentile 0.91848 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2019-16943.html