{"id":"CVE-2019-17531","details":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.","aliases":["GHSA-gjmw-vf9h-g25v"],"modified":"2026-05-15T12:03:51.817445622Z","published":"2019-10-12T21:15:08.570Z","related":["ALSA-2020:1644","openSUSE-SU-2024:10868-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"8.0"}]},{"vendor_product":"oracle:banking_platform","cpes":["cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"2.4.0"},{"last_affected":"2.4.1"},{"last_affected":"2.5.0"},{"last_affected":"2.6.0"},{"last_affected":"2.6.1"},{"last_affected":"2.6.2"},{"last_affected":"2.7.0"},{"last_affected":"2.7.1"},{"last_affected":"2.9.0"}]},{"vendor_product":"oracle:communications_billing_and_revenue_management","cpes":["cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.5.0.23.0"},{"last_affected":"12.0.0.3.0"}]},{"vendor_product":"oracle:communications_calendar_server","cpes":["cpe:2.3:a:oracle:communications_calendar_server:8.0.0.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_calendar_server:8.0.0.3.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"8.0.0.2.0"},{"last_affected":"8.0.0.3.0"}]},{"vendor_product":"oracle:communications_cloud_native_core_network_slice_selection_function","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"1.2.1"}]},{"vendor_product":"oracle:communications_evolved_communications_application_server","cpes":["cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.1"}]},{"vendor_product":"oracle:global_lifecycle_management_nextgen_oui_framework","cpes":["cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:13.9.4.2.2:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"},{"last_affected":"13.9.4.2.2"}]},{"vendor_product":"oracle:goldengate_application_adapters","cpes":["cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"19.1.0.0.0"}]},{"vendor_product":"oracle:jd_edwards_enterpriseone_orchestrator","cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:9.2:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"9.2"}]},{"vendor_product":"oracle:jd_edwards_enterpriseone_tools","cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"9.2"}]},{"vendor_product":"oracle:primavera_gateway","cpes":["cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:16.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:16.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_gateway:19.12.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"introduced":"17.7"},{"last_affected":"17.12.6"},{"introduced":"18.8.0"},{"last_affected":"18.8.8"},{"last_affected":"16.1"},{"last_affected":"16.2"},{"last_affected":"19.12.0"}]},{"vendor_product":"oracle:retail_merchandising_system","cpes":["cpe:2.3:a:oracle:retail_merchandising_system:15.0.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_merchandising_system:16.0.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"15.0.3"},{"last_affected":"16.0.2"},{"last_affected":"16.0.3"}]},{"vendor_product":"oracle:retail_sales_audit","cpes":["cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"14.1"}]},{"vendor_product":"oracle:siebel_engineering_-_installer_&_deployment","cpes":["cpe:2.3:a:oracle:siebel_engineering_-_installer_\\&_deployment:*:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"2.20.5"}]},{"vendor_product":"oracle:trace_file_analyzer","cpes":["cpe:2.3:a:oracle:trace_file_analyzer:12.2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:trace_file_analyzer:18c:*:*:*:*:*:*:*","cpe:2.3:a:oracle:trace_file_analyzer:19c:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.0.1"},{"last_affected":"18c"},{"last_affected":"19c"}]},{"vendor_product":"oracle:webcenter_portal","cpes":["cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"oracle:webcenter_sites","cpes":["cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"oracle:weblogic_server","cpes":["cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"redhat:jboss_enterprise_application_platform","cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.2"},{"last_affected":"7.3"}]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E"},{"type":"WEB","url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4192"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0159"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0160"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0161"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0164"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0445"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191024-0005/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/issues/2498"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}