CVE-2020-36183

high
Published 2021-01-07 · Modified 2026-05-06
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

Unsafe Deserialization in jackson-databind

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-36183

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpuoct2021.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpujan2022.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com/security-alerts/cpuapr2022.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.oracle.com//security-alerts/cpujul2021.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/FasterXML/jackson-databind/issues/3003

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.12.1-1
debian debianbullseyefixed2.12.1-1
debian debianforkyfixed2.12.1-1
debian debiansidfixed2.12.1-1
debian debiantrixiefixed2.12.1-1
debian debian9.0affected

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.fasterxml.jackson.core:jackson-databind>=2.7.00,<2.9.10.82.9.10.8
java Mavencom.fasterxml.jackson.core:jackson-databind>=2.0.0,<2.6.7.52.6.7.5
java MAVENcom.fasterxml.jackson.core:jackson-databind>= 2.0.0, < 2.6.7.52.6.7.5
java MAVENcom.fasterxml.jackson.core:jackson-databind>= 2.7.00, < 2.9.10.82.9.10.8

Application impact

VendorProductVersionsFixed
fasterxmljackson-databind{"startIncluding":"2.0.0","endExcluding":"2.6.7.5"}2.6.7.5
netappcloud_backup-
netappservice_level_manager-
oracleagile_plm9.3.6
oracleapplication_testing_suite13.3.0.1
oracleautovue_for_agile_product_lifecycle_management21.0.2
oraclebanking_corporate_lending_process_management14.2
oraclebanking_corporate_lending_process_management14.3
oraclebanking_corporate_lending_process_management14.5
oraclebanking_credit_facilities_process_management14.2
oraclebanking_credit_facilities_process_management14.3
oraclebanking_credit_facilities_process_management14.5
oraclebanking_extensibility_workbench14.2
oraclebanking_extensibility_workbench14.3
oraclebanking_extensibility_workbench14.5
oraclebanking_supply_chain_finance14.2
oraclebanking_supply_chain_finance14.3
oraclebanking_supply_chain_finance14.5
oraclebanking_treasury_management4.4
oraclebanking_virtual_account_management14.2.0
oraclebanking_virtual_account_management14.3.0
oraclebanking_virtual_account_management14.5.0
oracleblockchain_platform{"endIncluding":"21.1.2"}
oraclecommerce_platform{"startIncluding":"11.3.0","endIncluding":"11.3.2"}
oraclecommerce_platform11.2.0
oraclecommunications_billing_and_revenue_management7.5.0.23.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_cloud_native_core_policy1.14.0
oraclecommunications_cloud_native_core_unified_data_repository1.4.0
oraclecommunications_convergent_charging_controller12.0.4.0.0
oraclecommunications_diameter_signaling_route{"startIncluding":"8.0.0.0","endIncluding":"8.5.0.0"}
oraclecommunications_element_manager{"startIncluding":"8.2.0.0","endIncluding":"8.2.4.0"}
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_instant_messaging_server10.0.1.5.0
oraclecommunications_network_charging_and_control12.0.4.0.0
oraclecommunications_offline_mediation_controller12.0.0.3
oraclecommunications_policy_management12.5.0
oraclecommunications_pricing_design_center12.0.0.4.0
oraclecommunications_services_gatekeeper7.0
oraclecommunications_session_report_manager{"startIncluding":"8.0.0.0","endIncluding":"8.2.2.1"}
oraclecommunications_session_route_manager{"startIncluding":"8.2.0.0","endIncluding":"8.2.2.1"}
oraclecommunications_unified_inventory_management7.4.1
oracledata_integrator12.2.1.4.0
oracledocumaker12.6.0
oracledocumaker12.6.3
oracledocumaker12.6.4
oraclegoldengate_application_adapters19.1.0.0.0
oracleinsurance_policy_administration{"startIncluding":"11.1.0","endIncluding":"11.3.0"}
oracleinsurance_policy_administration11.0.2
oracleinsurance_rules_palette{"startIncluding":"11.1.0","endIncluding":"11.3.0"}
oracleinsurance_rules_palette11.0.2
oraclejd_edwards_enterpriseone_orchestrator{"endExcluding":"9.2.5.3"}9.2.5.3
oraclejd_edwards_enterpriseone_tools{"endExcluding":"9.2.5.3"}9.2.5.3
oracleprimavera_gateway{"startIncluding":"17.12.0","endIncluding":"17.12.11"}
oracleprimavera_gateway20.12.0
oracleprimavera_unifier{"startIncluding":"17.7","endIncluding":"17.12"}
oracleprimavera_unifier17.2
oracleprimavera_unifier18.8
oracleprimavera_unifier19.12
oracleprimavera_unifier20.12
oracleretail_customer_management_and_segmentation_foundation{"startIncluding":"16.0","endIncluding":"19.0"}
oracleretail_merchandising_system15.0.3
oracleretail_service_backbone14.1.3.2
oracleretail_service_backbone15.0.3.1
oracleretail_service_backbone16.0.3.0
oracleretail_xstore_point_of_service16.0.6
oracleretail_xstore_point_of_service17.0.4
oracleretail_xstore_point_of_service18.0.3
oracleretail_xstore_point_of_service19.0.2
oraclewebcenter_portal12.2.1.3.0
oraclewebcenter_portal12.2.1.4.0

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.