8.1
CVSSv3

CVE-2020-35490

Published: 17/12/2020 Updated: 08/09/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

FasterXML jackson-databind 2.x prior to 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fasterxml jackson-databind

netapp service level manager -

debian debian linux 9.0

oracle webcenter portal 12.2.1.3.0

oracle application testing suite 13.3.0.1

oracle banking platform 2.6.2

oracle agile plm 9.3.6

oracle webcenter portal 12.2.1.4.0

oracle communications services gatekeeper 7.0

oracle retail merchandising system 15.0.3

oracle banking platform 2.7.0

oracle banking platform 2.7.1

oracle banking platform 2.9.0

oracle communications evolved communications application server 7.1

oracle banking platform 2.8.0

oracle banking virtual account management 14.3.0

oracle insurance policy administration j2ee 11.2.0

oracle communications interactive session recorder 6.3

oracle communications interactive session recorder 6.4

oracle communications diameter signaling router

oracle communications unified inventory management 7.4.1

oracle retail xstore point of service 16.0.6

oracle retail xstore point of service 17.0.4

oracle retail xstore point of service 18.0.3

oracle retail xstore point of service 19.0.2

oracle banking platform 2.10.0

oracle communications cloud native core unified data repository 1.4.0

oracle autovue for agile product lifecycle management 21.0.2

oracle documaker 12.6.3

oracle documaker 12.6.4

oracle banking virtual account management 14.2.0

oracle banking virtual account management 14.5.0

oracle banking treasury management 14.4

oracle communications pricing design center 12.0.0.4.0

oracle communications cloud native core policy 1.14.0

oracle communications instant messaging server 10.0.1.5.0

oracle communications offline mediation controller 12.0.0.3

oracle blockchain platform

Vendor Advisories

Cosminexus Component Container contain the following vulnerabilities: CVE-2020-35490, CVE-2020-35491, CVE-2020-35728, CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189 Affected products and versions are listed below Ple ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2017-7525, CVE-2017-15095, CVE-2020-14389, CVE-2020-25694, CVE-2020-25695, CVE-2020-25696, CVE-2020-35490, CVE-2020-35491 Affected products and versions are listed below Please upgrade your version to the appropriate version ...