Permissions, Privileges, and Access Controls in jackson-databind - CVE-2019-14379

 

Permissions, Privileges, and Access Controls in jackson-databind - CVE-2019-14379

Published: August 5, 2019


Vulnerability identifier: #VU19933
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14379
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on a targeted system.

The vulnerability exists due to the "SubTypeValidator.java" file mishandles default typing when Ehcache is used. A remote attacker can send a request that submits malicious input to the targeted system and execute arbitrary code.


Affected software

jackson-databind
Red Hat Software Collections
Apple Xcode
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
OpenShift Logging
Dell Secure Connect Gateway
Oracle Communications Diameter Signaling Router (DSR)
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Openshift Application Runtimes
JD Edwards EnterpriseOne Tools
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
JD Edwards EnterpriseOne Orchestrator
Oracle Communications Instant Messaging Server
Siebel UI Framework
Siebel Engineering - Installer & Deployment
Fedora
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind

How to mitigate CVE-2019-14379

Install updates from vendor's website.

jackson-databind - update to 2.9.9.2
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Red Hat OpenShift Container Platform - update to 4.6.26
Dell Support Assist Enterprise - update to 4.00.06.00
OpenShift Logging - update to 5.0.3
Dell Secure Connect Gateway - update to 5.14.00.10
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
Apple Xcode - update to 13.3
Siebel UI Framework - update to 19.2
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Security Verify Governance - update to 10.0.1.0.4

External References

Related Security Bulletins