Permissions, Privileges, and Access Controls in jackson-databind - CVE-2019-14379
Published: August 5, 2019
Vulnerability identifier: #VU19933
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14379
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on a targeted system.
The vulnerability exists due to the "SubTypeValidator.java" file mishandles default typing when Ehcache is used. A remote attacker can send a request that submits malicious input to the targeted system and execute arbitrary code.
Affected software
jackson-databind
Red Hat Software Collections
Apple Xcode
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
OpenShift Logging
Dell Secure Connect Gateway
Oracle Communications Diameter Signaling Router (DSR)
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Openshift Application Runtimes
JD Edwards EnterpriseOne Tools
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
JD Edwards EnterpriseOne Orchestrator
Oracle Communications Instant Messaging Server
Siebel UI Framework
Siebel Engineering - Installer & Deployment
Fedora
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
Red Hat Software Collections
Apple Xcode
z/Transaction Processing Facility ( z/TPF)
Log Analysis
IBM Process Mining
OpenShift Logging
Dell Secure Connect Gateway
Oracle Communications Diameter Signaling Router (DSR)
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Apache Kafka
Cloudera Observability with IBM
Dell Support Assist Enterprise
Integration Designer
Storage Virtualize
Red Hat OpenShift Container Platform
Red Hat Openshift Application Runtimes
JD Edwards EnterpriseOne Tools
IBM Disconnected Log Collector
Fuse
JBoss Enterprise Application Platform
JD Edwards EnterpriseOne Orchestrator
Oracle Communications Instant Messaging Server
Siebel UI Framework
Siebel Engineering - Installer & Deployment
Fedora
watsonx.data
jackson-annotations
jackson-bom
jackson-core
jackson-databind
How to mitigate CVE-2019-14379
Install updates from vendor's website.
jackson-databind - update to 2.9.9.2
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Red Hat OpenShift Container Platform - update to 4.6.26
Dell Support Assist Enterprise - update to 4.00.06.00
OpenShift Logging - update to 5.0.3
Dell Secure Connect Gateway - update to 5.14.00.10
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
Apple Xcode - update to 13.3
Siebel UI Framework - update to 19.2
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Security Verify Governance - update to 10.0.1.0.4
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Apache Kafka - addressed in versions 2.2.2, 2.3.1
Cloudera Observability with IBM - update to 3.6.2
Red Hat OpenShift Container Platform - update to 4.6.26
Dell Support Assist Enterprise - update to 4.00.06.00
OpenShift Logging - update to 5.0.3
Dell Secure Connect Gateway - update to 5.14.00.10
Fuse - update to 7.6.0
JBoss Enterprise Application Platform - update to 7.2.4
Apple Xcode - update to 13.3
Siebel UI Framework - update to 19.2
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
jackson-annotations - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-bom - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-core - addressed in versions 2.9.9-1.fc29, 2.9.9-1.fc30, 2.9.9-1.fc31
jackson-databind - addressed in versions 2.9.9.3-1.fc29, 2.9.9.3-1.fc30, 2.9.9.3-1.fc31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Security Verify Governance - update to 10.0.1.0.4
External References
Related Security Bulletins
- Red Hat update for rh-maven35-jackson-databind
- Red Hat update for OpenShift Container Platform 4.1.18 logging-elasticsearch5
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 7
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 6
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 8
- Red Hat update for Red Hat OpenShift Application Runtimes Thorntail 2.5.0
- Red Hat update for OpenShift Container Platform logging-elasticsearch5-container
- Vert.x 3.8.3 update for Red Hat OpenShift Application Runtimes
- Apache Kafka update for jackson-databind
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in JD Edwards EnterpriseOne Orchestrator
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router (DSR)
- Multiple vulnerabilities in Siebel UI Framework
- Permissions, Privileges, and Access Controls in Siebel Engineering - Installer & Deployment
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat Openshift Logging
- Multiple vulnerabilities in Apple Xcode
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in Dell Secure Connect Gateway
- IBM Log Analysis update for FasterXML jackson-databind
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM watsonx.data
- IBM watsonx.data update for FasterXML jackson-databind
- Fedora 31 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Fedora 30 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Fedora 29 update for jackson-annotations, jackson-bom, jackson-core, jackson-databind
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM