{"id":"CVE-2019-16943","details":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.","aliases":["GHSA-fmmc-742q-jg75"],"modified":"2026-05-15T12:03:13.735499839Z","published":"2019-10-01T17:15:10.400Z","related":["ALSA-2020:1644"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","source":"CPE_FIELD","extracted_events":[{"last_affected":"8.0"},{"last_affected":"9.0"},{"last_affected":"10.0"}],"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"]},{"vendor_product":"fedoraproject:fedora","source":"CPE_FIELD","extracted_events":[{"last_affected":"30"},{"last_affected":"31"}],"cpes":["cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"]},{"vendor_product":"netapp:active_iq_unified_manager","source":"CPE_FIELD","extracted_events":[{"introduced":"7.3"},{"introduced":"7.3"},{"introduced":"9.5"}],"cpes":["cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"]},{"vendor_product":"oracle:banking_platform","source":"CPE_FIELD","extracted_events":[{"last_affected":"2.4.0"},{"last_affected":"2.4.1"},{"last_affected":"2.5.0"},{"last_affected":"2.6.0"},{"last_affected":"2.6.1"},{"last_affected":"2.6.2"},{"last_affected":"2.7.0"},{"last_affected":"2.7.1"},{"last_affected":"2.9.0"}],"cpes":["cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:communications_billing_and_revenue_management","source":"CPE_FIELD","extracted_events":[{"last_affected":"7.5.0.23.0"},{"last_affected":"12.0.0.3.0"}],"cpes":["cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:communications_calendar_server","source":"CPE_FIELD","extracted_events":[{"last_affected":"8.0.0.2.0"},{"last_affected":"8.0.0.3.0"}],"cpes":["cpe:2.3:a:oracle:communications_calendar_server:8.0.0.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_calendar_server:8.0.0.3.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:communications_cloud_native_core_network_slice_selection_function","source":"CPE_FIELD","extracted_events":[{"last_affected":"1.2.1"}],"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:communications_evolved_communications_application_server","source":"CPE_FIELD","extracted_events":[{"last_affected":"7.1"}],"cpes":["cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:global_lifecycle_management_nextgen_oui_framework","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"},{"last_affected":"13.9.4.2.2"}],"cpes":["cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:goldengate_application_adapters","source":"CPE_FIELD","extracted_events":[{"last_affected":"19.1.0.0.0"}],"cpes":["cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:jd_edwards_enterpriseone_orchestrator","source":"CPE_FIELD","extracted_events":[{"last_affected":"9.2"}],"cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:9.2:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:jd_edwards_enterpriseone_tools","source":"CPE_FIELD","extracted_events":[{"last_affected":"9.2"}],"cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:primavera_gateway","extracted_events":[{"introduced":"17.7"},{"last_affected":"17.12.6"},{"introduced":"18.8.0"},{"last_affected":"18.8.8"},{"last_affected":"16.1"},{"last_affected":"16.2"},{"last_affected":"19.12.0"}],"cpes":["cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:16.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:16.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:19.12.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:retail_merchandising_system","source":"CPE_FIELD","extracted_events":[{"last_affected":"15.0.3"},{"last_affected":"16.0.2"},{"last_affected":"16.0.3"}],"cpes":["cpe:2.3:a:oracle:retail_merchandising_system:15.0.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_merchandising_system:16.0.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:retail_sales_audit","source":"CPE_FIELD","extracted_events":[{"last_affected":"14.1"}],"cpes":["cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:siebel_engineering_-_installer_&_deployment","source":"CPE_FIELD","extracted_events":[{"last_affected":"2.20.5"}],"cpes":["cpe:2.3:a:oracle:siebel_engineering_-_installer_\\&_deployment:*:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:trace_file_analyzer","source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.0.1"},{"last_affected":"18c"},{"last_affected":"19c"}],"cpes":["cpe:2.3:a:oracle:trace_file_analyzer:12.2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:trace_file_analyzer:18c:*:*:*:*:*:*:*","cpe:2.3:a:oracle:trace_file_analyzer:19c:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:webcenter_portal","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}],"cpes":["cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:webcenter_sites","source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}],"cpes":["cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"]},{"source":"CPE_FIELD","vendor_product":"oracle:weblogic_server","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}],"cpes":["cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"]},{"vendor_product":"redhat:jboss_enterprise_application_platform","source":"CPE_FIELD","extracted_events":[{"last_affected":"7.2"},{"last_affected":"7.3"},{"last_affected":"7.2"},{"last_affected":"7.3"}],"cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/"},{"type":"WEB","url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0159"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0160"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0161"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0164"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0445"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191017-0006/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4542"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"REPORT","url":"https://seclists.org/bugtraq/2019/Oct/6"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/issues/2478"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}