FasterXML records
86 published records for vendor fasterxml.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 9
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data58
- CWE-184 Incomplete List of Disallowed Inputs6
- CWE-770 Allocation of Resources Without Limits or Throttling4
- CWE-611 Improper Restriction of XML External Entity Reference3
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
86 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2017-17485Proof of concept | FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 49.7% | Jan 10, 2018 |
50Plan | CVE-2017-7525Proof of concept | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticafasterxml · jackson-databind · CWE-184 | Critical9.8 | — | 37.7% | Feb 6, 2018 |
47Plan | CVE-2020-8840Proof of concept | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedifasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 26.6% | Feb 10, 2020 |
45Plan | CVE-2018-7489Proof of concept | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution becausefasterxml · jackson-databind · CWE-184 | Critical9.8 | — | 19.8% | Feb 26, 2018 |
45Plan | CVE-2020-9547Proof of concept | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqfasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 18.4% | Mar 2, 2020 |
45Plan | CVE-2020-9548Proof of concept | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anterofasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 18.3% | Mar 2, 2020 |
43Plan | CVE-2018-14718No exploit | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 12.7% | Jan 2, 2019 |
43Plan | CVE-2018-14721No exploit | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveragingfasterxml · jackson-databind · CWE-918 | Critical10.0 | — | 10.5% | Jan 2, 2019 |
42Plan | CVE-2019-14540Proof of concept | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 10.8% | Sep 15, 2019 |
42Plan | CVE-2018-19361No exploit | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa clasfasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 10.6% | Jan 2, 2019 |
42Plan | CVE-2018-19360No exploit | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transpfasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 10.6% | Jan 2, 2019 |
42Plan | CVE-2018-19362No exploit | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-commonfasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 10.6% | Jan 2, 2019 |
42Plan | CVE-2018-14719No exploit | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 9.7% | Jan 2, 2019 |
42Plan | CVE-2019-20330No exploit | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 8.6% | Jan 3, 2020 |
42Plan | CVE-2017-15095No exploit | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated userfasterxml · jackson-databind · CWE-184 | Critical9.8 | — | 8.4% | Feb 6, 2018 |
41Plan | CVE-2019-14379No exploit | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcachefasterxml · jackson-databind · CWE-1321 | Critical9.8 | — | 8.1% | Jul 29, 2019 |
41Plan | CVE-2018-14720No exploit | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to blocfasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 7.5% | Jan 2, 2019 |
41Plan | CVE-2018-11307No exploit | An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 5.7% | Jul 9, 2019 |
41Plan | CVE-2019-16942No exploit | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 5.7% | Oct 1, 2019 |
41Plan | CVE-2019-14892No exploit | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserializationfasterxml · jackson-databind · CWE-200 | Critical9.8 | — | 5.6% | Mar 2, 2020 |
41Plan | CVE-2019-17531No exploit | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 5.4% | Oct 12, 2019 |
40Plan | CVE-2019-16335No exploit | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 5.0% | Sep 15, 2019 |
40Plan | CVE-2019-16943No exploit | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 4.9% | Oct 1, 2019 |
40Plan | CVE-2019-17267No exploit | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.fasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 4.6% | Oct 6, 2019 |
40Plan | CVE-2020-9546No exploit | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hafasterxml · jackson-databind · CWE-502 | Critical9.8 | — | 4.6% | Mar 2, 2020 |
- CVE-2017-1748554Plan
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix
CriticalCVSS 9.8Proof of conceptEPSS 50%fasterxml · jackson-databindJan 10, 2018
- CVE-2017-752550Plan
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthentica
CriticalCVSS 9.8Proof of conceptEPSS 38%fasterxml · jackson-databindFeb 6, 2018
- CVE-2020-884047Plan
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedi
CriticalCVSS 9.8Proof of conceptEPSS 27%fasterxml · jackson-databindFeb 10, 2020
- CVE-2018-748945Plan
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because
CriticalCVSS 9.8Proof of conceptEPSS 20%fasterxml · jackson-databindFeb 26, 2018
- CVE-2020-954745Plan
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sq
CriticalCVSS 9.8Proof of conceptEPSS 18%fasterxml · jackson-databindMar 2, 2020
- CVE-2020-954845Plan
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.antero
CriticalCVSS 9.8Proof of conceptEPSS 18%fasterxml · jackson-databindMar 2, 2020
- CVE-2018-1471843Plan
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-
CriticalCVSS 9.8No exploitEPSS 13%fasterxml · jackson-databindJan 2, 2019
- CVE-2018-1472143Plan
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging
CriticalCVSS 10.0No exploitEPSS 10%fasterxml · jackson-databindJan 2, 2019
- CVE-2019-1454042Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.
CriticalCVSS 9.8Proof of conceptEPSS 11%fasterxml · jackson-databindSep 15, 2019
- CVE-2018-1936142Plan
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa clas
CriticalCVSS 9.8No exploitEPSS 11%fasterxml · jackson-databindJan 2, 2019
- CVE-2018-1936042Plan
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transp
CriticalCVSS 9.8No exploitEPSS 11%fasterxml · jackson-databindJan 2, 2019
- CVE-2018-1936242Plan
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common
CriticalCVSS 9.8No exploitEPSS 11%fasterxml · jackson-databindJan 2, 2019
- CVE-2018-1471942Plan
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-
CriticalCVSS 9.8No exploitEPSS 10%fasterxml · jackson-databindJan 2, 2019
- CVE-2019-2033042Plan
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CriticalCVSS 9.8No exploitEPSS 9%fasterxml · jackson-databindJan 3, 2020
- CVE-2017-1509542Plan
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user
CriticalCVSS 9.8No exploitEPSS 8%fasterxml · jackson-databindFeb 6, 2018
- CVE-2019-1437941Plan
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache
CriticalCVSS 9.8No exploitEPSS 8%fasterxml · jackson-databindJul 29, 2019
- CVE-2018-1472041Plan
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to bloc
CriticalCVSS 9.8No exploitEPSS 8%fasterxml · jackson-databindJan 2, 2019
- CVE-2018-1130741Plan
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5.
CriticalCVSS 9.8No exploitEPSS 6%fasterxml · jackson-databindJul 9, 2019
- CVE-2019-1694241Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.
CriticalCVSS 9.8No exploitEPSS 6%fasterxml · jackson-databindOct 1, 2019
- CVE-2019-1489241Plan
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization
CriticalCVSS 9.8No exploitEPSS 6%fasterxml · jackson-databindMar 2, 2020
- CVE-2019-1753141Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.
CriticalCVSS 9.8No exploitEPSS 5%fasterxml · jackson-databindOct 12, 2019
- CVE-2019-1633540Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.
CriticalCVSS 9.8No exploitEPSS 5%fasterxml · jackson-databindSep 15, 2019
- CVE-2019-1694340Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.
CriticalCVSS 9.8No exploitEPSS 5%fasterxml · jackson-databindOct 1, 2019
- CVE-2019-1726740Plan
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.
CriticalCVSS 9.8No exploitEPSS 5%fasterxml · jackson-databindOct 6, 2019
- CVE-2020-954640Plan
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.ha
CriticalCVSS 9.8No exploitEPSS 5%fasterxml · jackson-databindMar 2, 2020