CVE-2020-10650

HIGH WAF: Medium
CVSS 8.1 Published: 2022-12-26
CWE-502 CWE-502

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

WAF Coverage Analysis

Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack
Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack

Affected Software

VendorProductVersion
debiandebian_linux10.0
netappactive_iq_unified_manager-
netappactive_iq_unified_manager-
netappactive_iq_unified_manager-
fasterxmljackson-databindup to 2.9.10.4
fasterxmljackson-databind2.10.0
fasterxmljackson-databind2.10.0
fasterxmljackson-databind2.10.0
oracleretail_merchandising_system15.0
oracleretail_sales_audit14.1

References

Back to CVE Database