Skip to content
Noroxi

FasterXML records

86 published records for vendor fasterxml.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
9
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

86 records
  • FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix

    CriticalCVSS 9.8Proof of conceptEPSS 50%

    fasterxml · jackson-databindJan 10, 2018

  • A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthentica

    CriticalCVSS 9.8Proof of conceptEPSS 38%

    fasterxml · jackson-databindFeb 6, 2018

  • FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedi

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    fasterxml · jackson-databindFeb 10, 2020

  • FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because

    CriticalCVSS 9.8Proof of conceptEPSS 20%

    fasterxml · jackson-databindFeb 26, 2018

  • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sq

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    fasterxml · jackson-databindMar 2, 2020

  • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.antero

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    fasterxml · jackson-databindMar 2, 2020

  • FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-

    CriticalCVSS 9.8No exploitEPSS 13%

    fasterxml · jackson-databindJan 2, 2019

  • FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging

    CriticalCVSS 10.0No exploitEPSS 10%

    fasterxml · jackson-databindJan 2, 2019

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    fasterxml · jackson-databindSep 15, 2019

  • FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa clas

    CriticalCVSS 9.8No exploitEPSS 11%

    fasterxml · jackson-databindJan 2, 2019

  • FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transp

    CriticalCVSS 9.8No exploitEPSS 11%

    fasterxml · jackson-databindJan 2, 2019

  • FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common

    CriticalCVSS 9.8No exploitEPSS 11%

    fasterxml · jackson-databindJan 2, 2019

  • FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-

    CriticalCVSS 9.8No exploitEPSS 10%

    fasterxml · jackson-databindJan 2, 2019

  • FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

    CriticalCVSS 9.8No exploitEPSS 9%

    fasterxml · jackson-databindJan 3, 2020

  • A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user

    CriticalCVSS 9.8No exploitEPSS 8%

    fasterxml · jackson-databindFeb 6, 2018

  • SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache

    CriticalCVSS 9.8No exploitEPSS 8%

    fasterxml · jackson-databindJul 29, 2019

  • FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to bloc

    CriticalCVSS 9.8No exploitEPSS 8%

    fasterxml · jackson-databindJan 2, 2019

  • An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5.

    CriticalCVSS 9.8No exploitEPSS 6%

    fasterxml · jackson-databindJul 9, 2019

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.

    CriticalCVSS 9.8No exploitEPSS 6%

    fasterxml · jackson-databindOct 1, 2019

  • A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization

    CriticalCVSS 9.8No exploitEPSS 6%

    fasterxml · jackson-databindMar 2, 2020

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.

    CriticalCVSS 9.8No exploitEPSS 5%

    fasterxml · jackson-databindOct 12, 2019

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.

    CriticalCVSS 9.8No exploitEPSS 5%

    fasterxml · jackson-databindSep 15, 2019

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10.

    CriticalCVSS 9.8No exploitEPSS 5%

    fasterxml · jackson-databindOct 1, 2019

  • A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.

    CriticalCVSS 9.8No exploitEPSS 5%

    fasterxml · jackson-databindOct 6, 2019

  • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.ha

    CriticalCVSS 9.8No exploitEPSS 5%

    fasterxml · jackson-databindMar 2, 2020