CVE-2020-35728

high
Published 2020-12-27 · Modified 2024-02-18
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-35728

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-35728.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpuoct2021.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpujan2022.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpuapr2022.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com//security-alerts/cpujul2021.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/FasterXML/jackson-databind/issues/2999

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2.12.1-1
debian debianbullseyefixed2.12.1-1
debian debianforkyfixed2.12.1-1
debian debiansidfixed2.12.1-1
debian debiantrixiefixed2.12.1-1
debian debian9.0affected

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.fasterxml.jackson.core:jackson-databind>=2.0.0,<2.9.10.82.9.10.8

Application impact

VendorProductVersionsFixed
fasterxmljackson-databind{"startIncluding":"2.0.0","endExcluding":"2.6.7.5"}2.6.7.5
netappservice_level_manager-
oracleagile_plm9.3.6
oracleapplication_testing_suite13.3.0.1
oracleautovue21.0.2
oraclebanking_corporate_lending_process_management14.2
oraclebanking_corporate_lending_process_management14.3
oraclebanking_corporate_lending_process_management14.5
oraclebanking_credit_facilities_process_management14.2
oraclebanking_credit_facilities_process_management14.3
oraclebanking_credit_facilities_process_management14.5
oraclebanking_extensibility_workbench14.2
oraclebanking_extensibility_workbench14.3
oraclebanking_extensibility_workbench14.5
oraclebanking_supply_chain_finance14.2
oraclebanking_supply_chain_finance14.3
oraclebanking_supply_chain_finance14.5
oraclebanking_treasury_management14.4
oraclebanking_virtual_account_management14.2.0
oraclebanking_virtual_account_management14.3.0
oraclebanking_virtual_account_management14.5.0
oracleblockchain_platform{"endIncluding":"21.1.2"}
oraclecommerce_platform{"startIncluding":"11.3.0","endIncluding":"11.3.2"}
oraclecommerce_platform11.2.0
oraclecommunications_billing_and_revenue_management7.5.0.23.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_cloud_native_core_policy1.14.0
oraclecommunications_cloud_native_core_unified_data_repository1.4.0
oraclecommunications_convergent_charging_controller12.0.4.0.0
oraclecommunications_diameter_signaling_route{"startIncluding":"8.0.0.0","endIncluding":"8.5.0.0"}
oraclecommunications_element_manager{"startIncluding":"8.2.0.0","endIncluding":"8.2.4.0"}
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_network_charging_and_control12.0.4.0.0
oraclecommunications_policy_management12.5.0
oraclecommunications_services_gatekeeper7.0
oraclecommunications_session_report_manager{"startIncluding":"8.0.0.0","endIncluding":"8.2.2.1"}
oraclecommunications_session_route_manager{"startIncluding":"8.2.0.0","endIncluding":"8.2.2.1"}
oraclecommunications_unified_inventory_management7.4.1
oracledata_integrator12.2.1.4.0
oraclegoldengate_application_adapters19.1.0.0.0
oracleinsurance_policy_administration{"startIncluding":"11.1.0","endIncluding":"11.3.0"}
oracleinsurance_policy_administration11.0.2
oracleinsurance_rules_palette{"startIncluding":"11.1.0","endIncluding":"11.3.0"}
oracleinsurance_rules_palette11.0.2
oraclejd_edwards_enterpriseone_orchestrator{"endExcluding":"9.2.5.3"}9.2.5.3
oraclejd_edwards_enterpriseone_tools{"endExcluding":"9.2.5.3"}9.2.5.3
oracleprimavera_gateway{"startIncluding":"17.12.0","endIncluding":"17.12.11"}
oracleprimavera_gateway20.12.0
oracleprimavera_unifier{"startIncluding":"17.7","endIncluding":"17.12"}
oracleprimavera_unifier20.12
oracleretail_customer_management_and_segmentation_foundation{"startIncluding":"16.0","endIncluding":"19.0"}
oracleretail_merchandising_system15.0.3
oracleretail_service_backbone14.1.3.2
oracleretail_service_backbone15.0.3.1
oracleretail_service_backbone16.0.3.0
oracleretail_xstore_point_of_service16.0.6
oracleretail_xstore_point_of_service17.0.4
oracleretail_xstore_point_of_service18.0.3
oracleretail_xstore_point_of_service19.0.2
oraclewebcenter_portal12.2.1.3.0
oraclewebcenter_portal12.2.1.4.0

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.