Description


jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Related CPE's


a

fasterxml

jackson-databind

2



a

oracle

commerce_platform

3




a

oracle

communications_cloud_native_core_network_repository_function

2

a

oracle

communications_cloud_native_core_network_slice_selection_function

2




a

oracle

financial_services_analytical_applications_infrastructure

4

a

oracle

financial_services_behavior_detection_platform

3

a

oracle

financial_services_crime_and_compliance_management_studio

2

a

oracle

financial_services_enterprise_case_management

5

a

oracle

financial_services_trade-based_anti_money_laundering

2

a

oracle

global_lifecycle_management_nextgen_oui_framework

2




a

oracle

peoplesoft_enterprise_peopletools

2

a

oracle

primavera_gateway

5

a

oracle

primavera_p6_enterprise_project_portfolio_management

4

a

oracle

primavera_unifier

5


a

oracle

sd-wan_edge

2


a

oracle

utilities_framework

6

a

oracle

weblogic_server

3

o

debian

debian_linux

3

a

netapp

active_iq_unified_manager

3




Weaknesses



CWE-787

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.5 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-03-11T07:15:07.800

3 years ago

Last modified

2022-11-29T22:12:38.183

2 years ago