Input validation error in Codehaus jackson - CVE-2019-10202

 

Input validation error in Codehaus jackson - CVE-2019-10202

Published: October 1, 2019


Vulnerability identifier: #VU21470
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10202
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to incorrect implementation of patch for Codehaus 1.9.x against insufficient data deserialization present in FasterXML jackson-databind. A remote attacker can bypass implemented protection measures and exploit known deserialization vulnerabilities in jackson-databind package.

Affected software

Codehaus jackson
z/Transaction Processing Facility ( z/TPF)
IBM PureData System for Operational Analytics
Log Analysis
IBM Process Mining
IBM Intelligent Operations Center
QRadar User Behavior Analytics
IBM Match 360
IBM UrbanCode Release
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Spectrum Protect Plus
Cloudera Observability with IBM
Integration Designer
IBM Application Suite - IBM Asset Data Dictionary Component
Storage Copy Data Management
UrbanCode Build
StreamSets Data Collector
Storage Virtualize
JBoss Enterprise Application Platform
Opensuse
Voice Gateway
IBM Disconnected Log Collector
IBM Cloud Pak System

How to mitigate CVE-2019-10202

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002, 1.3.7.2 IF003
IBM Process Mining - update to 1.12.0.4
Cloudera Observability with IBM - update to 3.6.2
IBM Intelligent Operations Center - update to 5.2.4
JBoss Enterprise Application Platform - update to 7.2.4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
IBM Disconnected Log Collector - update to 1.8.3
Storage Copy Data Management - update to 2.2.26.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
QRadar User Behavior Analytics - update to 4.1.9
IBM Match 360 - update to 4.7.1
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
StreamSets Data Collector - update to 7.0.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Security Verify Governance - update to 10.0.1.0.4
IBM Spectrum Protect Plus - update to 10.1.6.4

External References

Related Security Bulletins