#VU19943 Deserialization of Untrusted Data in jackson-databind - CVE-2018-12023
Published: August 6, 2019
jackson-databind
FasterXML
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists when Default Typing is enabled and the service has the Oracle JDBC jar in the classpath. A remote attacker can provide an LDAP service to access and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.