CVE-2020-35728

HIGH WAF: Medium
CVSS 8.1 Published: 2020-12-27
CWE-502 CWE-502

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

WAF Coverage Analysis

Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack
Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack

Affected Software

VendorProductVersion
fasterxmljackson-databind2.9.0 - 2.9.10.8
debiandebian_linux9.0
netappservice_level_manager-
oracleagile_plm9.3.6
oracleapplication_testing_suite13.3.0.1
oracleautovue21.0.2
oraclebanking_corporate_lending_process_management14.2
oraclebanking_corporate_lending_process_management14.3
oraclebanking_corporate_lending_process_management14.5
oraclebanking_credit_facilities_process_management14.2

References

Back to CVE Database