Deserialization of untrusted data in jackson-databind - CVE-2017-17485

 

Deserialization of untrusted data in jackson-databind - CVE-2017-17485

Published: January 26, 2018


Vulnerability identifier: #VU10257
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17485
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the FasterXML jackson-databind library due to improper validation of user-input handled by the readValue method of the ObjectMapper object. A remote attacker can send malicious input to the vulnerable method of a web application that uses the Spring library in the application's classpath and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

jackson-databind
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
StreamSets Data Collector
CloudLink
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Virtualization
Red Hat Virtualization Host
JBoss Enterprise Application Platform
Fuse
watsonx.data
rh-eclipse46-jackson-databind (Red Hat package)
jackson-databind
eap7-jboss-ec2-eap (Red Hat package)
Vue PACS

How to mitigate CVE-2017-17485

The vulnerability is addressed in the following versions: 2.7.9.2 and 2.8.11.

Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
IBM Business Automation Workflow - update to 18.0.0.1
watsonx.data - addressed in versions 2.0.2, 2.0.3
rh-eclipse46-jackson-databind (Red Hat package) - update to 2.6.3-2.6.el7
jackson-databind - addressed in versions 2.7.6-8.fc26, 2.7.6-8.fc27
StreamSets Data Collector - update to 7.0.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
CloudLink - update to 8.0-3.10.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Vue PACS - update to 12.2.8.410
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins