Deserialization of untrusted data in jackson-databind - CVE-2018-7489
Published: March 26, 2018
Vulnerability identifier: #VU11268
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7489
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and execute arbitrary code on the target system.
The weakness exists in the readValue method due to improper validation of user-input. A remote attacker can send malicious JSON input, bypass security restrictions and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the readValue method due to improper validation of user-input. A remote attacker can send malicious JSON input, bypass security restrictions and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
jackson-databind
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
Sterling Connect Direct File Agent
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
Oracle Financial Services Analytical Applications Infrastructure
Multi-Enterprise Integration Gateway
B2B Advanced Communications
StreamSets Data Collector
Storage Virtualize
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
Red Hat Virtualization
rhvm-appliance (Red Hat package)
jackson-databind
JBoss Enterprise Application Platform
Oracle WebLogic Server
IBM Qradar SIEM
Oracle Financial Services Hedge Management and IFRS Valuations
Oracle Financial Services Market Risk Measurement and Management
IBM InfoSphere Information Server
Oracle Database Server
watsonx.data
Cloudera Data Platform Private Cloud Base for IBM
RSA Authentication Manager
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
Sterling Connect Direct File Agent
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
Oracle Financial Services Analytical Applications Infrastructure
Multi-Enterprise Integration Gateway
B2B Advanced Communications
StreamSets Data Collector
Storage Virtualize
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
Red Hat Virtualization
rhvm-appliance (Red Hat package)
jackson-databind
JBoss Enterprise Application Platform
Oracle WebLogic Server
IBM Qradar SIEM
Oracle Financial Services Hedge Management and IFRS Valuations
Oracle Financial Services Market Risk Measurement and Management
IBM InfoSphere Information Server
Oracle Database Server
watsonx.data
Cloudera Data Platform Private Cloud Base for IBM
RSA Authentication Manager
How to mitigate CVE-2018-7489
Update to version 2.8.11.1.
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
rhvm-appliance (Red Hat package) - update to 4.2-20180620.0.el7
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Business Automation Workflow - update to 18.0.0.1
Multi-Enterprise Integration Gateway - update to 1.0.0.8
B2B Advanced Communications - update to 1.0.0.8
Sterling Connect Direct File Agent - update to 1.4.0.2.8
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-databind - update to 2.9.4-3.fc28
StreamSets Data Collector - update to 7.0.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
RSA Authentication Manager - update to 8.7 Patch 3
NetWorker - update to 19.10.0.0
Robotic Process Automation for Cloud Pak - update to 21.0.7
Dell Support Assist Enterprise - update to 4.00.06.00
rhvm-appliance (Red Hat package) - update to 4.2-20180620.0.el7
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Business Automation Workflow - update to 18.0.0.1
Multi-Enterprise Integration Gateway - update to 1.0.0.8
B2B Advanced Communications - update to 1.0.0.8
Sterling Connect Direct File Agent - update to 1.4.0.2.8
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-databind - update to 2.9.4-3.fc28
StreamSets Data Collector - update to 7.0.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
RSA Authentication Manager - update to 8.7 Patch 3
NetWorker - update to 19.10.0.0
Robotic Process Automation for Cloud Pak - update to 21.0.7
External References
Related Security Bulletins
- Remote code execution in FasterXML jackson-databind
- Multiple vulnerabilities in Oracle Financial Services Applications
- Debian update for jackson-databind
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for OpenShift Container Platform 4.1.18 logging-elasticsearch5
- Red Hat update for OpenShift Container Platform logging-elasticsearch5-container
- Multiple vulnerabilities in Oracle Database Server
- Red Hat Virtualization update for rhvm-appliance
- Remote code execution in IBM Sterling Connect:Direct File Agent
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM B2B Advanced Communications
- IBM QRadar SIEM update for third-party components
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM watsonx.data
- IBM watsonx.data update for FasterXML jackson-databind
- Fedora 28 update for jackson-databind
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM StreamSets Data Collector
- Multiple vulnerabilities in IBM InfoSphere Information Server