fasterxml security advisories
18 threat alerts tracking vulnerabilities and security advisories that affect fasterxml products.
Vulnios monitors fasterxml CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent fasterxml security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2017-15095 — fasterxml, debian — jackson-databind, debian_linux
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafte
criticalCVE-2017-15095Critical Vulnerability: CVE-2017-7525 — fasterxml, debian — jackson-databind, debian_linux
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciousl
criticalCVE-2017-7525Critical Vulnerability: CVE-2019-14893 — fasterxml, netapp — jackson-databind, oncommand_api_services
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when us
criticalCVE-2019-14893Critical Vulnerability: CVE-2019-17531 — fasterxml, debian — jackson-databind, debian_linux
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON
criticalCVE-2019-17531Critical Vulnerability: CVE-2019-16335 — fasterxml, fedoraproject — jackson-databind, fedora
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
criticalCVE-2019-16335Critical Vulnerability: CVE-2019-14892 — fasterxml, redhat — jackson-databind, decision_manager
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 J
criticalCVE-2019-14892Critical Vulnerability: CVE-2019-14379 — fasterxml, debian — jackson-databind, debian_linux
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leadi
criticalCVE-2019-14379Critical Vulnerability: CVE-2019-16942 — fasterxml, debian — jackson-databind, debian_linux
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON
criticalCVE-2019-16942Critical Vulnerability: CVE-2018-14718 — fasterxml, debian — jackson-databind, debian_linux
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
criticalCVE-2018-14718Critical Vulnerability: CVE-2019-14540 — fasterxml, netapp — jackson-databind, oncommand_api_services
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
criticalCVE-2019-14540Critical Vulnerability: CVE-2018-14719 — fasterxml, debian — jackson-databind, debian_linux
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserializ
criticalCVE-2018-14719Critical Vulnerability: CVE-2020-8840 — fasterxml, debian — jackson-databind, debian_linux
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
criticalCVE-2020-8840Critical Vulnerability: CVE-2018-11307 — fasterxml, redhat — jackson-databind, openshift_container_platform
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.
criticalCVE-2018-11307Critical Vulnerability: CVE-2019-20330 — fasterxml, oracle — jackson-databind, banking_platform
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
criticalCVE-2019-20330Critical Vulnerability: CVE-2020-9547 — fasterxml, netapp — jackson-databind, active_iq_unified_manager
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis
criticalCVE-2020-9547Critical Vulnerability: CVE-2019-16943 — fasterxml, debian — jackson-databind, debian_linux
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON
criticalCVE-2019-16943Critical Vulnerability: CVE-2019-17267 — fasterxml, netapp — jackson-databind, active_iq_unified_manager
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
criticalCVE-2019-17267Critical Vulnerability: CVE-2020-9548 — fasterxml, netapp — jackson-databind, active_iq_unified_manager
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
criticalCVE-2020-9548
Track fasterxml exposure across your environment
Vulnios automatically cross-references your asset inventory against new fasterxml CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan