CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2019-16943: jackson-databind from 2.0.0 (inclusive), before 2.6.7.3 (exclusive), from 2.7.0 (inclusive), before 2.8.11.5…

CVE-2019-16943. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.04901 (percentile 0.91848), scored 2026-10-06.

Affected technology

jackson-databind · from 2.0.0 (inclusive), before 2.6.7.3 (exclusive)
fasterxml

jackson-databind · from 2.7.0 (inclusive), before 2.8.11.5 (exclusive)
fasterxml

jackson-databind · from 2.9.0 (inclusive), before 2.9.10.1 (exclusive)
fasterxml

debian linux · 8.0
debian

debian linux · 9.0
debian

debian linux · 10.0
debian

fedora · 30
fedoraproject

fedora · 31
fedoraproject

jboss enterprise application platform · 7.2
redhat

jboss enterprise application platform · 7.3
redhat

banking platform · 2.4.0
oracle

banking platform · 2.4.1
oracle

banking platform · 2.5.0
oracle

banking platform · 2.6.0
oracle

banking platform · 2.6.1
oracle

banking platform · 2.6.2
oracle

banking platform · 2.7.0
oracle

banking platform · 2.7.1
oracle

banking platform · 2.9.0
oracle

communications billing and revenue management · 7.5.0.23.0
oracle

communications billing and revenue management · 12.0.0.3.0
oracle

communications calendar server · 8.0.0.2.0
oracle

communications calendar server · 8.0.0.3.0
oracle

communications cloud native core network slice selection function · 1.2.1
oracle

communications evolved communications application server · 7.1
oracle

global lifecycle management nextgen oui framework · 12.2.1.3.0
oracle

global lifecycle management nextgen oui framework · 12.2.1.4.0
oracle

global lifecycle management nextgen oui framework · 13.9.4.2.2
oracle

goldengate application adapters · 19.1.0.0.0
oracle

jd edwards enterpriseone orchestrator · 9.2
oracle

jd edwards enterpriseone tools · 9.2
oracle

primavera gateway · from 17.7 (inclusive), through 17.12.6 (inclusive)
oracle

primavera gateway · from 18.8.0 (inclusive), through 18.8.8 (inclusive)
oracle

primavera gateway · 16.1
oracle

primavera gateway · 16.2
oracle

primavera gateway · 19.12.0
oracle

retail merchandising system · 15.0.3
oracle

retail merchandising system · 16.0.2
oracle

retail merchandising system · 16.0.3
oracle

retail sales audit · 14.1
oracle

siebel engineering - installer & deployment · through 2.20.5 (inclusive)
oracle

trace file analyzer · 12.2.0.1
oracle

trace file analyzer · 18c
oracle

trace file analyzer · 19c
oracle

webcenter portal · 12.2.1.3.0
oracle

webcenter portal · 12.2.1.4.0
oracle

webcenter sites · 12.2.1.3.0
oracle

webcenter sites · 12.2.1.4.0
oracle

weblogic server · 12.2.1.3.0
oracle

weblogic server · 12.2.1.4.0
oracle

active iq unified manager · from 7.3 (inclusive)
netapp

active iq unified manager · from 9.5 (inclusive)
netapp

oncommand api services · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

service level manager · Version not applicable in the source CPE
netapp

steelstore cloud integrated storage · Version not applicable in the source CPE
netapp

n/a · n/a
Vendor not specified by the source

Description’s affected range: through 2.9.10

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-502
CCR priority
40.4 /100 (P3)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.04901 · percentile 0.91848 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2019-16943.html