Information disclosure in jackson-databind - CVE-2019-12814

 

Information disclosure in jackson-databind - CVE-2019-12814

Published: July 2, 2019 / Updated: September 16, 2019


Vulnerability identifier: #VU18961
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12814
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access sensitive information on a targeted system.

The vulnerability exist due to a polymorphic typing issue when Default Typing is enabled. A remote attacker can send a crafted JSON message that submits malicious input and gain access to sensitive information on the targeted system.



Affected software

jackson-databind
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Oracle Retail Customer Management and Segmentation Foundation
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
Operational Decision Manager
Vue PACS

How to mitigate CVE-2019-12814

Install update from vendor's website..

jackson-databind - addressed in versions 2.7.9.6, 2.8.11.4, 2.9.9.1
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Security Verify Governance - update to 10.0.1.0.4
Vue PACS - update to 12.2.8.410

External References

Related Security Bulletins