Deserialization of untrusted data in jackson-databind - CVE-2018-7489

 

Deserialization of untrusted data in jackson-databind - CVE-2018-7489

Published: March 26, 2018


Vulnerability identifier: #VU11268
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7489
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and execute arbitrary code on the target system.

The weakness exists in the readValue method due to improper validation of user-input. A remote attacker can send malicious JSON input, bypass security restrictions and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

jackson-databind
Debian Linux
Fedora
z/Transaction Processing Facility ( z/TPF)
IBM Business Process Manager
IBM Business Automation Workflow
Sterling Connect Direct File Agent
IBM Cloud Application Performance Management (APM)
NetWorker
Cloudera Observability with IBM
Dell Support Assist Enterprise
Oracle Financial Services Analytical Applications Infrastructure
Multi-Enterprise Integration Gateway
B2B Advanced Communications
StreamSets Data Collector
Storage Virtualize
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
Red Hat Virtualization
rhvm-appliance (Red Hat package)
jackson-databind
JBoss Enterprise Application Platform
Oracle WebLogic Server
IBM Qradar SIEM
Oracle Financial Services Hedge Management and IFRS Valuations
Oracle Financial Services Market Risk Measurement and Management
IBM InfoSphere Information Server
Oracle Database Server
watsonx.data
Cloudera Data Platform Private Cloud Base for IBM
RSA Authentication Manager

How to mitigate CVE-2018-7489

Update to version 2.8.11.1.

Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
rhvm-appliance (Red Hat package) - update to 4.2-20180620.0.el7
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Business Automation Workflow - update to 18.0.0.1
Multi-Enterprise Integration Gateway - update to 1.0.0.8
B2B Advanced Communications - update to 1.0.0.8
Sterling Connect Direct File Agent - update to 1.4.0.2.8
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-databind - update to 2.9.4-3.fc28
StreamSets Data Collector - update to 7.0.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
RSA Authentication Manager - update to 8.7 Patch 3
NetWorker - update to 19.10.0.0
Robotic Process Automation for Cloud Pak - update to 21.0.7

External References

Related Security Bulletins