CVE-2020-11619

high
Published 2020-04-07 · Modified 2026-05-06
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

jackson-databind mishandles the interaction between serialization gadgets and typing

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-11619

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/FasterXML/jackson-databind/issues/2680

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.11.1-1
debian debianbullseyefixed2.11.1-1
debian debianforkyfixed2.11.1-1
debian debiansidfixed2.11.1-1
debian debiantrixiefixed2.11.1-1
debian debian8.0affected

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.fasterxml.jackson.core:jackson-databind>=2.9.0,<2.9.10.42.9.10.4
java MAVENcom.fasterxml.jackson.core:jackson-databind>= 2.9.0, <= 2.9.10.32.9.10.4

Application impact

VendorProductVersionsFixed
fasterxmljackson-databind{"startIncluding":"2.0.0","endExcluding":"2.9.10.4"}2.9.10.4
netappactive_iq_unified_manager{"startIncluding":"7.3"}
netappsteelstore_cloud_integrated_storage-
oracleagile_plm9.3.6
oraclebanking_platform{"startIncluding":"2.4.0","endIncluding":"2.9.0"}
oraclecommunications_calendar_server8.0.0.4.0
oraclecommunications_contacts_server8.0.0.4.0
oraclecommunications_contacts_server8.0.0.5.0
oraclecommunications_diameter_signaling_router{"startIncluding":"8.0.0","endIncluding":"8.2.2"}
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_instant_messaging_server10.0.1.4.0
oraclecommunications_network_charging_and_control{"startIncluding":"12.0.0","endIncluding":"12.0.3"}
oraclecommunications_network_charging_and_control6.0.1
oracleenterprise_manager_base_platform13.3.0.0
oracleenterprise_manager_base_platform13.4.0.0
oracleglobal_lifecycle_management_opatch{"endExcluding":"12.2.0.1.20"}12.2.0.1.20
oraclejd_edwards_enterpriseone_orchestrator{"endExcluding":"9.2.4.2"}9.2.4.2
oraclejd_edwards_enterpriseone_tools{"endExcluding":"9.2.4.2"}9.2.4.2
oracleprimavera_unifier{"startIncluding":"17.7","endIncluding":"17.12"}
oracleprimavera_unifier16.1
oracleprimavera_unifier16.2
oracleprimavera_unifier18.8
oracleprimavera_unifier19.12
oracleretail_merchandising_system15.0
oracleretail_sales_audit14.1
oracleretail_xstore_point_of_service15.0
oracleretail_xstore_point_of_service16.0
oracleretail_xstore_point_of_service17.0
oracleretail_xstore_point_of_service18.0
oracleretail_xstore_point_of_service19.0
oracleweblogic_server12.2.1.3.0
oracleweblogic_server12.2.1.4.0

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.