8.1
CVSSv3

CVE-2020-24616

CVSSv4: NA | CVSSv3: 8.1 | CVSSv2: 6.8 | VMScore: 910 | EPSS: 0.0072 | KEV: Not Included
Published: 25/08/2020 Updated: 21/11/2024

Vulnerability Summary

FasterXML jackson-databind 2.x prior to 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fasterxml jackson-databind

netapp active iq unified manager -

oracle agile plm 9.3.6

oracle application testing suite 13.3.0.1

oracle autovue for agile product lifecycle management 21.0.2

oracle banking liquidity management 14.2

oracle banking liquidity management 14.3

oracle banking liquidity management 14.5

oracle banking supply chain finance 14.2

oracle banking supply chain finance 14.3

oracle banking supply chain finance 14.5

oracle blockchain platform

oracle communications calendar server 8.0

oracle communications calendar server 8.0.0.4.0

oracle communications cloud native core unified data repository 1.4.0

oracle communications contacts server 8.0

oracle communications contacts server 8.0.0.5.0

oracle communications diameter signaling router

oracle communications element manager

oracle communications evolved communications application server 7.1

oracle communications instant messaging server 10.0.1.5.0

oracle communications messaging server 8.1

oracle communications offline mediation controller 12.0.0.3

oracle communications policy management 12.5.0

oracle communications pricing design center 12.0.0.4.0

oracle communications services gatekeeper 7.0

oracle communications session report manager

oracle communications unified inventory management 7.4.1

oracle identity manager connector 11.1.1.5.0

oracle siebel ui framework

debian debian linux 9.0

Vendor Advisories

Cosminexus Component Container contain the following vulnerabilities: CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, CVE-2019-14439, CVE-2019-14540, CVE-2019-14892, CVE-2019-14893, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-20 ...

Github Repositories

cve-2020-24616 poc

cve-2020-24616-poc cve-2020-24616 poc java菜鸟写的第一个poc 参考了很多Jndi注入的Poc