Known vulnerabilities in rh-maven35-jackson-databind (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-maven35-jackson-databind_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 20
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-maven35-jackson-databind (Red Hat package) rh-maven35-jackson-databind (Red Hat package) is affected by 20 known vulnerabilities: 15 high, 3 medium, 2 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU48979 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-25649
CWE-611 Medium
No
No
2.7.6-2.12.el7 03.12.2020 SB2020121510
SB2021020321
SB2021042112
and 68 more
#VU47105 - Deserialization of Untrusted Data
CVE-2020-24750
CWE-502 High
Available
No
2.7.6-2.11.el7 17.09.2020 SB2020092506
SB2020100512
SB2021012013
and 28 more
#VU27032 - Deserialization of Untrusted Data
CVE-2020-11620
CWE-502 High
No
No
2.7.6-2.10.el7 20.04.2020 SB2020030909
SB2020052628
SB2020073033
and 15 more
#VU27031 - Deserialization of Untrusted Data
CVE-2020-11619
CWE-502 High
No
No
2.7.6-2.10.el7 20.04.2020 SB2020030909
SB2020052628
SB2020073033
and 15 more
#VU26492 - Deserialization of Untrusted Data
CVE-2020-10969
CWE-502 High
No
No
2.7.6-2.9.el7 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 14 more
#VU26491 - Deserialization of Untrusted Data
CVE-2020-10968
CWE-502 High
No
No
2.7.6-2.9.el7 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 15 more
#VU26490 - Deserialization of Untrusted Data
CVE-2020-11113
CWE-502 High
Available
No
2.7.6-2.9.el7 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 16 more
#VU26489 - Deserialization of Untrusted Data
CVE-2020-11112
CWE-502 High
No
No
2.7.6-2.9.el7 01.04.2020 SB2020030909
SB2020042318
SB2020073033
and 16 more
#VU26488 - Deserialization of Untrusted Data
CVE-2020-11111
CWE-502 High
No
No
2.7.6-2.9.el7 31.03.2020 SB2020030909
SB2020042318
SB2020073033
and 16 more
#VU19943 - Deserialization of Untrusted Data
CVE-2018-12023
CWE-502 Medium
No
No
2.7.6-2.5.el7 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 20 more
#VU19942 - Deserialization of Untrusted Data
CVE-2018-12022
CWE-502 Medium
No
No
2.7.6-2.5.el7 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 18 more
#VU19938 - Deserialization of Untrusted Data
CVE-2018-11307
CWE-502 High
No
No
2.7.6-2.5.el7 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 17 more
#VU19018 - Deserialization of Untrusted Data
CVE-2019-12384
CWE-502 High
No
No
2.7.6-2.6.el7 04.07.2019 SB2019091218
SB2019092703
SB2019100116
and 28 more
#VU17781 - Improper input validation
CVE-2018-19362
CWE-20 High
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 38 more
#VU17780 - Improper input validation
CVE-2018-19360
CWE-20 High
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17779 - Improper input validation
CVE-2018-19361
CWE-20 High
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 23 more
#VU17778 - Improper input validation
CVE-2018-14719
CWE-20 High
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17777 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2018-14720
CWE-611 Low
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 21 more
#VU17776 - Server-Side Request Forgery (SSRF)
CVE-2018-14721
CWE-918 Low
No
No
2.7.6-2.5.el7 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 23 more
#VU17053 - Permissions, Privileges, and Access Controls
CVE-2018-14718
CWE-264 High
No
No
2.7.6-2.5.el7 17.01.2019 SB2019011703
SB2019052407
SB2019091718
and 29 more