6.8
CVSSv2

CVE-2020-24750

Published: 17/09/2020 Updated: 13/09/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

FasterXML jackson-databind 2.x prior to 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fasterxml jackson-databind

oracle application testing suite 13.3.0.1

oracle agile plm 9.3.6

oracle communications policy management 12.5.0

oracle communications diameter signaling router

oracle communications offline mediation controller 12.0.0.3.0

oracle communications services gatekeeper 7.0

oracle communications contacts server 8.0.0.5.0

oracle communications calendar server 8.0.0.4.0

oracle banking credit facilities process management 14.3.0

oracle banking corporate lending process management 14.3.0

oracle siebel core - server framework

oracle communications unified inventory management 7.4.1

oracle communications element manager

oracle autovue for agile product lifecycle management 21.0.2

oracle banking supply chain finance 14.2.0

oracle banking credit facilities process management 14.2.0

oracle banking credit facilities process management 14.5.0

oracle banking corporate lending process management 14.2.0

oracle banking corporate lending process management 14.5.0

oracle banking supply chain finance 14.5.0

oracle banking supply chain finance 14.3.0

oracle communications messaging server 8.1

oracle siebel ui framework

oracle identity manager connector 11.1.1.5.0

oracle communications contacts server 8.0

oracle communications calendar server 8.0

oracle banking liquidity management 14.3

oracle banking liquidity management 14.5

oracle banking liquidity management 14.2

oracle communications session route manager

oracle communications session report manager

oracle communications pricing design center 12.0.0.4.0

oracle communications instant messaging server 10.0.1.5.0

oracle blockchain platform

debian debian linux 9.0

Vendor Advisories

Synopsis Low: OpenShift Container Platform 4340 security and bug fix update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat OpenShift Container Platform 43Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring S ...
Synopsis Important: rh-maven35-jackson-databind security update Type/Severity Security Advisory: Important Topic An update for rh-maven35-jackson-databind is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Cosminexus Component Container contain the following vulnerabilities: CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, CVE-2019-14439, CVE-2019-14540, CVE-2019-14892, CVE-2019-14893, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-20 ...

Github Repositories

CVE-2020-24750

CVE-2020-24750 Result: