Information disclosure in jackson-databind - CVE-2019-12814

 

Information disclosure in jackson-databind - CVE-2019-12814

Published: July 2, 2019 / Updated: September 16, 2019


Vulnerability identifier: #VU18961
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-12814
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
jackson-databind
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Oracle Retail Customer Management and Segmentation Foundation
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
Operational Decision Manager
Vue PACS

Detailed vulnerability description

The vulnerability allows a remote attacker to access sensitive information on a targeted system.

The vulnerability exist due to a polymorphic typing issue when Default Typing is enabled. A remote attacker can send a crafted JSON message that submits malicious input and gain access to sensitive information on the targeted system.



How to mitigate CVE-2019-12814

Install update from vendor's website..

Sources