CVE-2020-14060

high
Published 2020-06-14 · Modified 2026-05-06
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

Deserialization of untrusted data in Jackson Databind

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-14060

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/FasterXML/jackson-databind/issues/2688

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.11.1-1
debian debianbullseyefixed2.11.1-1
debian debianforkyfixed2.11.1-1
debian debiansidfixed2.11.1-1
debian debiantrixiefixed2.11.1-1

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.fasterxml.jackson.core:jackson-databind>=2.9.0,<2.9.10.52.9.10.5
java MAVENcom.fasterxml.jackson.core:jackson-databind>= 2.9.0, <= 2.9.10.42.9.10.5

Application impact

VendorProductVersionsFixed
fasterxmljackson-databind{"startIncluding":"2.0.0","endExcluding":"2.9.10.5"}2.9.10.5
netappactive_iq_unified_manager{"startIncluding":"7.3"}
netappsteelstore_cloud_integrated_storage-
oracleagile_plm9.3.6
oraclebanking_digital_experience18.1
oraclebanking_digital_experience18.2
oraclebanking_digital_experience18.3
oraclebanking_digital_experience19.1
oraclebanking_digital_experience19.2
oraclebanking_digital_experience20.1
oraclecommunications_calendar_server8.0.0.4.0
oraclecommunications_contacts_server8.0.0.5.0
oraclecommunications_diameter_signaling_router{"startIncluding":"8.0.0","endIncluding":"8.2.2"}
oraclecommunications_element_manager{"startIncluding":"8.2.0","endIncluding":"8.2.2"}
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_session_report_manager{"startIncluding":"8.2.0","endIncluding":"8.2.2"}
oraclecommunications_session_route_manager{"startIncluding":"8.2.0","endIncluding":"8.2.2"}

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.