6.8
CVSSv2

CVE-2020-11113

Published: 31/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

FasterXML jackson-databind 2.x prior to 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fasterxml jackson-databind

debian debian linux 8.0

netapp steelstore cloud integrated storage -

oracle retail xstore point of service 15.0

oracle primavera unifier 16.2

oracle retail service backbone 14.1

oracle primavera unifier 16.1

oracle retail service backbone 15.0

oracle weblogic server 12.2.1.3.0

oracle webcenter portal 12.2.1.3.0

oracle retail xstore point of service 16.0

oracle primavera unifier 18.8

oracle primavera unifier

oracle retail merchandising system 15.0

oracle agile plm 9.3.6

oracle banking digital experience 18.2

oracle banking digital experience 18.3

oracle banking digital experience 19.1

oracle banking digital experience 18.1

oracle weblogic server 12.2.1.4.0

oracle enterprise manager base platform 13.3.0.0

oracle financial services price creation and discovery 8.0.7

oracle primavera unifier 19.12

oracle financial services analytical applications infrastructure

oracle webcenter portal 12.2.1.4.0

oracle enterprise manager base platform 13.4.0.0

oracle communications instant messaging server 10.0.1.4.0

oracle retail xstore point of service 17.0

oracle retail xstore point of service 18.0

oracle retail xstore point of service 19.0

oracle communications diameter signaling router

oracle banking digital experience 19.2

oracle financial services price creation and discovery 8.0.6

oracle banking digital experience 20.1

oracle financial services institutional performance analytics 8.1.0

oracle financial services institutional performance analytics 8.0.6

oracle financial services institutional performance analytics 8.0.7

oracle insurance policy administration j2ee 11.0.2.25

oracle insurance policy administration j2ee 11.1.0.15

oracle financial services retail customer analytics 8.0.6

oracle retail sales audit 14.1

oracle communications evolved communications application server 7.1

oracle communications network charging and control 6.0.1

oracle retail service backbone 16.0

oracle jd edwards enterpriseone tools

oracle jd edwards enterpriseone orchestrator

oracle communications network charging and control

oracle banking platform

oracle global lifecycle management opatch

oracle communications contacts server 8.0.0.5.0

oracle communications calendar server 8.0.0.4.0

oracle communications session route manager

oracle communications session report manager

oracle communications element manager

oracle autovue for agile product lifecycle management 21.0.2

Vendor Advisories

Synopsis Important: Red Hat Data Grid 737 security update Type/Severity Security Advisory: Important Topic An update for Red Hat Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Important: Red Hat Process Automation Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...
Synopsis Important: Red Hat Decision Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Moderate: Red Hat Single Sign-On 740 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 74 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerab ...
Synopsis Moderate: AMQ Clients 280 Release Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat AMQ Clients 280Red Hat Product Security has rated this update as having a Moderate security impact A Common Vulnerability Scoring System (CVSS) base score, which gives a de ...
Synopsis Important: EAP Continuous Delivery Technical Preview Release 19 security update Type/Severity Security Advisory: Important Topic This is a security update for JBoss EAP Continuous Delivery 19Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabi ...
Synopsis Important: rh-maven35-jackson-databind security update Type/Severity Security Advisory: Important Topic An update for rh-maven35-jackson-databind is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat build of Thorntail 251 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of ThorntailRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: Red Hat Fuse 770 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 76 to 77) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...
Cosminexus Component Container contain the following vulnerabilities: CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, CVE-2019-14439, CVE-2019-14540, CVE-2019-14892, CVE-2019-14893, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-20 ...

Github Repositories

CVE-2020-11113:Jackson-databind RCE

CVE-2020-11113 CVE-2020-11113:Jackson-databind RCE