Deserialization of untrusted data in jackson-databind - CVE-2017-17485
Published: January 26, 2018
Vulnerability identifier: #VU10257
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17485
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the FasterXML jackson-databind library due to improper validation of user-input handled by the readValue method of the ObjectMapper object. A remote attacker can send malicious input to the vulnerable method of a web application that uses the Spring library in the application's classpath and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the FasterXML jackson-databind library due to improper validation of user-input handled by the readValue method of the ObjectMapper object. A remote attacker can send malicious input to the vulnerable method of a web application that uses the Spring library in the application's classpath and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
jackson-databind
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
StreamSets Data Collector
CloudLink
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Virtualization
Red Hat Virtualization Host
JBoss Enterprise Application Platform
Fuse
watsonx.data
rh-eclipse46-jackson-databind (Red Hat package)
jackson-databind
eap7-jboss-ec2-eap (Red Hat package)
Vue PACS
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
StreamSets Data Collector
CloudLink
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Virtualization
Red Hat Virtualization Host
JBoss Enterprise Application Platform
Fuse
watsonx.data
rh-eclipse46-jackson-databind (Red Hat package)
jackson-databind
eap7-jboss-ec2-eap (Red Hat package)
Vue PACS
How to mitigate CVE-2017-17485
The vulnerability is addressed in the following versions: 2.7.9.2 and 2.8.11.
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
IBM Business Automation Workflow - update to 18.0.0.1
watsonx.data - addressed in versions 2.0.2, 2.0.3
rh-eclipse46-jackson-databind (Red Hat package) - update to 2.6.3-2.6.el7
jackson-databind - addressed in versions 2.7.6-8.fc26, 2.7.6-8.fc27
StreamSets Data Collector - update to 7.0.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
CloudLink - update to 8.0-3.10.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Vue PACS - update to 12.2.8.410
NetWorker - update to 19.10.0.0
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
IBM Business Automation Workflow - update to 18.0.0.1
watsonx.data - addressed in versions 2.0.2, 2.0.3
rh-eclipse46-jackson-databind (Red Hat package) - update to 2.6.3-2.6.el7
jackson-databind - addressed in versions 2.7.6-8.fc26, 2.7.6-8.fc27
StreamSets Data Collector - update to 7.0.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
CloudLink - update to 8.0-3.10.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Vue PACS - update to 12.2.8.410
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Remote code execution in FasterXML jackson-databind
- Debian update for jackson-databind
- Red Hat update for jackson-databind
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for OpenShift Container Platform 4.1.18 logging-elasticsearch5
- Red Hat update for OpenShift Container Platform logging-elasticsearch5-container
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in IBM Business Automation Workflow
- Red Hat Software Collections update for rh-eclipse46-jackson-databind
- Red Hat JBoss Enterprise Application Platform 7.1.1 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.1 for Red Hat Enterprise Linux 7 update for eap7-jboss-ec2-eap
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in Philips Vue PACS
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM watsonx.data
- IBM watsonx.data update for FasterXML jackson-databind
- Fedora 27 update for jackson-databind
- Fedora 26 update for jackson-databind
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM StreamSets Data Collector