[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-15095 -- libjackson2-databind-java

Deprecated
ID: oval:org.secpod.oval:def:1901541Date: (C)2019-03-04   (M)2023-12-20
Class: VULNERABILITYFamily: unix




A deserialization flaw was discovered in the libjackson2-databind-java in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
libjackson2-databind-java
Reference:
CVE-2017-15095
CVE    1
CVE-2017-15095
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:fasterxml:libjackson2-databind-java

© SecPod Technologies