Information disclosure in jackson-databind - CVE-2019-12814
Published: July 2, 2019 / Updated: September 16, 2019
Vulnerability identifier: #VU18961
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12814
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to access sensitive information on a targeted system.
The vulnerability exist due to a polymorphic typing issue when Default Typing is enabled. A remote attacker can send a crafted JSON message that submits malicious input and gain access to sensitive information on the targeted system.
Affected software
jackson-databind
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Oracle Retail Customer Management and Segmentation Foundation
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
Operational Decision Manager
Vue PACS
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Oracle Retail Customer Management and Segmentation Foundation
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
Operational Decision Manager
Vue PACS
How to mitigate CVE-2019-12814
Install update from vendor's website..
jackson-databind - addressed in versions 2.7.9.6, 2.8.11.4, 2.9.9.1
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Security Verify Governance - update to 10.0.1.0.4
Vue PACS - update to 12.2.8.410
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Security Verify Governance - update to 10.0.1.0.4
Vue PACS - update to 12.2.8.410
External References
Related Security Bulletins
- Information disclosure in FasterXML jackson-databind
- Red Hat update for OpenShift Container Platform 4.1.18 logging-elasticsearch5
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 7
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 6
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 8
- Red Hat update for OpenShift Container Platform logging-elasticsearch5-container
- Apache Kafka update for jackson-databind
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- Red Hat Enterprise Linux 8 update for the pki-core:10.6 and pki-deps:10:6 modules
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in z/Transaction Processing Facility
- IBM Log Analysis update for FasterXML jackson-databind
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in Philips Vue PACS
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM watsonx.data
- IBM watsonx.data update for FasterXML jackson-databind
- Fedora 31 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Fedora 30 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Fedora 29 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM