8.1
CVSSv3

CVE-2020-36188

CVSSv4: NA | CVSSv3: 8.1 | CVSSv2: 6.8 | VMScore: 910 | EPSS: 0.15849 | KEV: Not Included
Published: 06/01/2021 Updated: 21/11/2024

Vulnerability Summary

FasterXML jackson-databind 2.x prior to 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fasterxml jackson-databind

netapp cloud backup -

netapp service level manager -

debian debian linux 9.0

oracle agile plm 9.3.6

oracle application testing suite 13.3.0.1

oracle autovue for agile product lifecycle management 21.0.2

oracle banking corporate lending process management 14.2

oracle banking corporate lending process management 14.3

oracle banking corporate lending process management 14.5

oracle banking credit facilities process management 14.2

oracle banking credit facilities process management 14.3

oracle banking credit facilities process management 14.5

oracle banking extensibility workbench 14.2

oracle banking extensibility workbench 14.3

oracle banking extensibility workbench 14.5

oracle banking supply chain finance 14.2

oracle banking supply chain finance 14.3

oracle banking supply chain finance 14.5

oracle banking treasury management 4.4

oracle banking virtual account management 14.2.0

oracle banking virtual account management 14.3.0

oracle banking virtual account management 14.5.0

oracle blockchain platform

oracle commerce platform

oracle commerce platform 11.2.0

oracle communications billing and revenue management 7.5.0.23.0

oracle communications billing and revenue management 12.0.0.3.0

oracle communications cloud native core policy 1.14.0

oracle communications cloud native core unified data repository 1.4.0

oracle communications convergent charging controller 12.0.4.0.0

oracle communications diameter signaling route

oracle communications element manager

oracle communications evolved communications application server 7.1

oracle communications instant messaging server 10.0.1.5.0

oracle communications network charging and control 12.0.4.0.0

oracle communications offline mediation controller 12.0.0.3

oracle communications policy management 12.5.0

oracle communications pricing design center 12.0.0.4.0

oracle communications services gatekeeper 7.0

oracle communications session report manager

oracle communications session route manager

oracle communications unified inventory management 7.4.1

oracle data integrator 12.2.1.4.0

oracle documaker 12.6.0

oracle documaker 12.6.3

oracle documaker 12.6.4

oracle goldengate application adapters 19.1.0.0.0

oracle insurance policy administration

oracle insurance policy administration 11.0.2

oracle insurance rules palette

oracle insurance rules palette 11.0.2

oracle jd edwards enterpriseone orchestrator

oracle jd edwards enterpriseone tools

oracle primavera gateway

oracle primavera gateway 20.12.0

oracle primavera unifier

oracle primavera unifier 17.2

oracle primavera unifier 18.8

oracle primavera unifier 19.12

oracle primavera unifier 20.12

oracle retail customer management and segmentation foundation

oracle retail merchandising system 15.0.3

oracle retail service backbone 14.1.3.2

oracle retail service backbone 15.0.3.1

oracle retail service backbone 16.0.3.0

oracle retail xstore point of service 16.0.6

oracle retail xstore point of service 17.0.4

oracle retail xstore point of service 18.0.3

oracle retail xstore point of service 19.0.2

oracle webcenter portal 12.2.1.3.0

oracle webcenter portal 12.2.1.4.0

Vendor Advisories

Cosminexus Component Container contain the following vulnerabilities: CVE-2020-35490, CVE-2020-35491, CVE-2020-35728, CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189 Affected products and versions are listed below Ple ...