A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
{
"unresolved_ranges": [
{
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
]
},
{
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "30"
},
{
"last_affected": "31"
}
]
},
{
"vendor_product": "netapp:active_iq_unified_manager",
"cpes": [
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:*",
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*",
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "7.3"
},
{
"introduced": "7.3"
},
{
"introduced": "9.5"
}
]
},
{
"vendor_product": "oracle:banking_platform",
"cpes": [
"cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "2.4.0"
},
{
"last_affected": "2.4.1"
},
{
"last_affected": "2.5.0"
},
{
"last_affected": "2.6.0"
},
{
"last_affected": "2.6.1"
},
{
"last_affected": "2.6.2"
},
{
"last_affected": "2.7.0"
},
{
"last_affected": "2.7.1"
},
{
"last_affected": "2.9.0"
}
]
},
{
"vendor_product": "oracle:communications_billing_and_revenue_management",
"cpes": [
"cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.5.0.23.0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"vendor_product": "oracle:communications_calendar_server",
"cpes": [
"cpe:2.3:a:oracle:communications_calendar_server:8.0.0.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_calendar_server:8.0.0.3.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.0.0.2.0"
},
{
"last_affected": "8.0.0.3.0"
}
]
},
{
"vendor_product": "oracle:communications_cloud_native_core_network_slice_selection_function",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.2.1"
}
]
},
{
"vendor_product": "oracle:communications_evolved_communications_application_server",
"cpes": [
"cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.1"
}
]
},
{
"vendor_product": "oracle:database_server",
"cpes": [
"cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.2.0.1"
},
{
"last_affected": "18c"
},
{
"last_affected": "19c"
}
]
},
{
"vendor_product": "oracle:global_lifecycle_management_nextgen_oui_framework",
"cpes": [
"cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
},
{
"last_affected": "13.9.4.2.2"
}
]
},
{
"vendor_product": "oracle:goldengate_application_adapters",
"cpes": [
"cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "19.1.0.0.0"
}
]
},
{
"vendor_product": "oracle:jd_edwards_enterpriseone_orchestrator",
"cpes": [
"cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:9.2:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.2"
}
]
},
{
"vendor_product": "oracle:jd_edwards_enterpriseone_tools",
"cpes": [
"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.2"
}
]
},
{
"vendor_product": "oracle:primavera_gateway",
"cpes": [
"cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_gateway:19.12.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "17.12.0"
},
{
"last_affected": "17.12.6"
},
{
"introduced": "18.8.0"
},
{
"last_affected": "18.8.8"
},
{
"last_affected": "19.12.0"
}
]
},
{
"vendor_product": "oracle:primavera_unifier",
"cpes": [
"cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "17.7"
},
{
"last_affected": "17.12"
},
{
"last_affected": "16.1"
},
{
"last_affected": "16.2"
},
{
"last_affected": "18.8"
},
{
"last_affected": "19.12"
}
]
},
{
"vendor_product": "oracle:retail_merchandising_system",
"cpes": [
"cpe:2.3:a:oracle:retail_merchandising_system:15.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_merchandising_system:16.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.0.3"
},
{
"last_affected": "16.0.2"
},
{
"last_affected": "16.0.3"
}
]
},
{
"vendor_product": "oracle:retail_sales_audit",
"cpes": [
"cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "14.1"
}
]
},
{
"vendor_product": "oracle:siebel_engineering_-_installer_&_deployment",
"cpes": [
"cpe:2.3:a:oracle:siebel_engineering_-_installer_\\&_deployment:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "2.20.5"
}
]
},
{
"vendor_product": "oracle:siebel_ui_framework",
"cpes": [
"cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:siebel_ui_framework:20.6:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "20.5"
},
{
"last_affected": "20.6"
}
]
},
{
"vendor_product": "oracle:webcenter_portal",
"cpes": [
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"vendor_product": "oracle:webcenter_sites",
"cpes": [
"cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"vendor_product": "oracle:weblogic_server",
"cpes": [
"cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"vendor_product": "redhat:jboss_enterprise_application_platform",
"cpes": [
"cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.2.0"
},
{
"last_affected": "7.3"
}
]
}
]
}{
"cpe": "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.6.7.3"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.8.11.5"
},
{
"introduced": "2.9.0"
},
{
"fixed": "2.9.10.1"
}
]
}