Improper input validation in Oracle NoSQL Database - CVE-2018-14721

 

Improper input validation in Oracle NoSQL Database - CVE-2018-14721

Published: June 4, 2020


Vulnerability identifier: #VU28622
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14721
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the NoSQL (jackson-databind) component in Oracle NoSQL Database. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle NoSQL Database
Fedora
bouncycastle
jackson-parent
jackson-dataformats-binary
jackson-modules-base
jackson-module-jsonSchema
jackson-jaxrs-providers
jackson-datatypes-collections
jackson-datatype-joda
jackson-datatype-jdk8
jackson-dataformats-text
jackson-dataformat-xml
jackson-databind
jackson-core
jackson-bom
jackson-annotations
eclipse-jgit
eclipse-linuxtools
Red Hat Single Sign-On

How to mitigate CVE-2018-14721

Install updates from vendor's website.

Oracle NoSQL Database - update to 19.3.12
bouncycastle - update to 1.61-1.fc29
jackson-parent - update to 2.9.1.2-1.fc29
jackson-dataformats-binary - update to 2.9.8-1.fc29
jackson-modules-base - update to 2.9.8-1.fc29
jackson-module-jsonSchema - update to 2.9.8-1.fc29
jackson-jaxrs-providers - update to 2.9.8-1.fc29
jackson-datatypes-collections - update to 2.9.8-1.fc29
jackson-datatype-joda - update to 2.9.8-1.fc29
jackson-datatype-jdk8 - update to 2.9.8-1.fc29
jackson-dataformats-text - update to 2.9.8-1.fc29
jackson-dataformat-xml - update to 2.9.8-1.fc29
jackson-databind - update to 2.9.8-1.fc29
jackson-core - update to 2.9.8-1.fc29
jackson-bom - update to 2.9.8-1.fc29
jackson-annotations - update to 2.9.8-1.fc29
eclipse-jgit - update to 5.2.0-4.fc29
eclipse-linuxtools - update to 7.1.0-3.fc29
Red Hat Single Sign-On - update to 7.3.1

External References

Related Security Bulletins