CVE-2019-16942
CRITICALFasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
Title source: ruleDescription
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Exploits (2)
nomisec
STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2019-16942-jackson-databind-vulnerable
nomisec
STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2019-16942-jackson-databind-vulnerable
References (29)
... and 9 more
Scores
CVSS v3
9.8
EPSS
0.0042
EPSS Percentile
61.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (49)
com.fasterxml.jackson.core/jackson-databind
2.9.0 - 2.9.10.1Maven
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
fasterxml/jackson-databind
2.0.0 - 2.6.7.3
fedoraproject/fedora
30
fedoraproject/fedora
31
netapp/active_iq_unified_manager
7.3 (2 CPE variants)
netapp/active_iq_unified_manager
9.5
netapp/oncommand_api_services
... and 39 more
Published
Oct 01, 2019
Tracked Since
Feb 18, 2026