A flaw was found in jackson-databind prior to 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fasterxml jackson-databind |
||
netapp active iq unified manager - |
||
netapp oncommand api services - |
||
netapp oncommand insight - |
||
netapp service level manager - |
||
apache nifi |
||
debian debian linux 9.0 |
||
oracle commerce guided search and experience manager 11.3.2 |