// For flags

CVE-2020-24616

 

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

FasterXML jackson-databind versiones 2.x anteriores a 2.9.10.6, maneja inapropiadamente la interacción entre los dispositivos de serialización y la escritura, relacionada con br.com.anteros.dbcp.AnterosDBCPDataSource (también se conoce como Anteros-DBCP)

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-25 CVE Reserved
  • 2020-08-25 CVE Published
  • 2024-07-16 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fasterxml
Search vendor "Fasterxml"
Jackson-databind
Search vendor "Fasterxml" for product "Jackson-databind"
>= 2.0.0 < 2.9.10.6
Search vendor "Fasterxml" for product "Jackson-databind" and version " >= 2.0.0 < 2.9.10.6"
-
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
-linux
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
-vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
-windows
Affected
Oracle
Search vendor "Oracle"
Agile Plm
Search vendor "Oracle" for product "Agile Plm"
9.3.6
Search vendor "Oracle" for product "Agile Plm" and version "9.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.3.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Autovue For Agile Product Lifecycle Management
Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management"
21.0.2
Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" and version "21.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Liquidity Management
Search vendor "Oracle" for product "Banking Liquidity Management"
14.2
Search vendor "Oracle" for product "Banking Liquidity Management" and version "14.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Liquidity Management
Search vendor "Oracle" for product "Banking Liquidity Management"
14.3
Search vendor "Oracle" for product "Banking Liquidity Management" and version "14.3"
-
Affected
Oracle
Search vendor "Oracle"
Banking Liquidity Management
Search vendor "Oracle" for product "Banking Liquidity Management"
14.5
Search vendor "Oracle" for product "Banking Liquidity Management" and version "14.5"
-
Affected
Oracle
Search vendor "Oracle"
Banking Supply Chain Finance
Search vendor "Oracle" for product "Banking Supply Chain Finance"
14.2
Search vendor "Oracle" for product "Banking Supply Chain Finance" and version "14.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Supply Chain Finance
Search vendor "Oracle" for product "Banking Supply Chain Finance"
14.3
Search vendor "Oracle" for product "Banking Supply Chain Finance" and version "14.3"
-
Affected
Oracle
Search vendor "Oracle"
Banking Supply Chain Finance
Search vendor "Oracle" for product "Banking Supply Chain Finance"
14.5
Search vendor "Oracle" for product "Banking Supply Chain Finance" and version "14.5"
-
Affected
Oracle
Search vendor "Oracle"
Blockchain Platform
Search vendor "Oracle" for product "Blockchain Platform"
< 21.1.2
Search vendor "Oracle" for product "Blockchain Platform" and version " < 21.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Calendar Server
Search vendor "Oracle" for product "Communications Calendar Server"
8.0
Search vendor "Oracle" for product "Communications Calendar Server" and version "8.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Calendar Server
Search vendor "Oracle" for product "Communications Calendar Server"
8.0.0.4.0
Search vendor "Oracle" for product "Communications Calendar Server" and version "8.0.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Unified Data Repository
Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository"
1.4.0
Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository" and version "1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Contacts Server
Search vendor "Oracle" for product "Communications Contacts Server"
8.0
Search vendor "Oracle" for product "Communications Contacts Server" and version "8.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Contacts Server
Search vendor "Oracle" for product "Communications Contacts Server"
8.0.0.5.0
Search vendor "Oracle" for product "Communications Contacts Server" and version "8.0.0.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Element Manager
Search vendor "Oracle" for product "Communications Element Manager"
>= 8.2.0 <= 8.2.4.0
Search vendor "Oracle" for product "Communications Element Manager" and version " >= 8.2.0 <= 8.2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Evolved Communications Application Server
Search vendor "Oracle" for product "Communications Evolved Communications Application Server"
7.1
Search vendor "Oracle" for product "Communications Evolved Communications Application Server" and version "7.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Instant Messaging Server
Search vendor "Oracle" for product "Communications Instant Messaging Server"
10.0.1.5.0
Search vendor "Oracle" for product "Communications Instant Messaging Server" and version "10.0.1.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Messaging Server
Search vendor "Oracle" for product "Communications Messaging Server"
8.1
Search vendor "Oracle" for product "Communications Messaging Server" and version "8.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Offline Mediation Controller
Search vendor "Oracle" for product "Communications Offline Mediation Controller"
12.0.0.3
Search vendor "Oracle" for product "Communications Offline Mediation Controller" and version "12.0.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Policy Management
Search vendor "Oracle" for product "Communications Policy Management"
12.5.0
Search vendor "Oracle" for product "Communications Policy Management" and version "12.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Pricing Design Center
Search vendor "Oracle" for product "Communications Pricing Design Center"
12.0.0.4.0
Search vendor "Oracle" for product "Communications Pricing Design Center" and version "12.0.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Services Gatekeeper
Search vendor "Oracle" for product "Communications Services Gatekeeper"
7.0
Search vendor "Oracle" for product "Communications Services Gatekeeper" and version "7.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Report Manager
Search vendor "Oracle" for product "Communications Session Report Manager"
>= 8.0.0.0 <= 8.2.2.1
Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.0.0.0 <= 8.2.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.1
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.1"
-
Affected
Oracle
Search vendor "Oracle"
Identity Manager Connector
Search vendor "Oracle" for product "Identity Manager Connector"
11.1.1.5.0
Search vendor "Oracle" for product "Identity Manager Connector" and version "11.1.1.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Siebel Ui Framework
Search vendor "Oracle" for product "Siebel Ui Framework"
<= 21.2
Search vendor "Oracle" for product "Siebel Ui Framework" and version " <= 21.2"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected