Логотип exploitDog
bind:CVE-2019-16943
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-16943

Количество 8

Количество 8

ubuntu логотип

CVE-2019-16943

больше 5 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-16943

больше 5 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-16943

больше 5 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-16943

больше 5 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fmmc-742q-jg75

больше 5 лет назад

jackson-databind polymorphic typing issue

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2019-04777

больше 5 лет назад

Уязвимость компонента P6DataSource библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю получить несанкционированный доступ к информации или вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2020-1644

около 5 лет назад

ELSA-2020-1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2020:1644

около 5 лет назад

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
redhat логотип
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-fmmc-742q-jg75

jackson-databind polymorphic typing issue

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
fstec логотип
BDU:2019-04777

Уязвимость компонента P6DataSource библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю получить несанкционированный доступ к информации или вызвать отказ в обслуживании

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
oracle-oval логотип
ELSA-2020-1644

ELSA-2020-1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (MODERATE)

около 5 лет назад
rocky логотип
RLSA-2020:1644

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

около 5 лет назад

Уязвимостей на страницу