Remote code execution in jackson-databind - CVE-2017-15095

 

Remote code execution in jackson-databind - CVE-2017-15095

Published: December 8, 2017 / Updated: October 8, 2018


Vulnerability identifier: #VU9607
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15095
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the jackson-databind development library due to improper implementation of blacklists for input handled by the ObjectMapper object readValue method. A remote unauthenticated attacker can send a malicious input and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

jackson-databind
Debian Linux
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
z/Transaction Processing Facility ( z/TPF)
Oracle Communications Diameter Signaling Router (DSR)
IBM Cloud Application Performance Management (APM)
Cloudera Observability with IBM
Dell Support Assist Enterprise
StreamSets Data Collector
Storage Virtualize
Red Hat OpenShift Container Platform
JBoss Enterprise Application Platform
Fuse
IBM Cognos Business Intelligence Server
IBM Cognos Analytics
libjackson-json-java (Ubuntu package)
rh-eclipse46-jackson-databind (Red Hat package)
rh-eclipse47-jackson-databind (Red Hat package)
jackson-databind
eap7-jboss-ec2-eap (Red Hat package)
watsonx.data

How to mitigate CVE-2017-15095

Install update from vendor's website.

jackson-databind - addressed in versions 2.8.10, 2.9.1
Cloudera Observability with IBM - update to 3.6.2
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.5.0
IBM Cognos Analytics - update to 11.0.13
libjackson-json-java (Ubuntu package) - update to 1.9.2-7ubuntu0.2
watsonx.data - addressed in versions 2.0.2, 2.0.3
rh-eclipse46-jackson-databind (Red Hat package) - addressed in versions 2.6.3-2.4.el7, 2.6.3-2.6.el7
rh-eclipse47-jackson-databind (Red Hat package) - update to 2.7.6-3.3.el7
jackson-databind - addressed in versions 2.7.6-5.fc26, 2.7.6-5.fc27, 2.7.6-8.fc26, 2.7.6-8.fc27
StreamSets Data Collector - update to 7.0.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0

External References

Related Security Bulletins