CVE-2018-14721: SSRF
Published Jan 2, 2019
·Updated
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Affected Software
46 affected componentsFixes available
debian/jackson-databind
2.9.8-3+deb10u32.9.8-3+deb10u52.12.1-1+deb11u12.14.0-1
redhat/jackson-databind<2.9.7
2.9.7
redhat/jackson-databind<2.7.9.5
2.7.9.5
redhat/jackson-databind<2.8.11.3
2.8.11.3
fasterxml jackson-databind>=2.6.0<2.6.7.2
fasterxml jackson-databind>=2.7.0<2.7.9.5
fasterxml jackson-databind>=2.8.0<2.8.11.3
fasterxml jackson-databind>=2.9.0<2.9.7
fasterxml jackson-databind=2.7.0-rc1
fasterxml jackson-databind=2.7.0-rc2
fasterxml jackson-databind=2.7.0-rc3
fasterxml jackson-databind=2.8.0-rc1
fasterxml jackson-databind=2.8.0-rc2
fasterxml jackson-databind=2.9.0-pr1
fasterxml jackson-databind=2.9.0-pr2
fasterxml jackson-databind=2.9.0-pr3
fasterxml jackson-databind=2.9.0-pr4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Oracle Banking Platform=2.5.0
Oracle Banking Platform=2.6.0
Oracle Banking Platform=2.6.1
Oracle Banking Platform=2.6.2
Oracle Communications Billing and Revenue Management=7.5
Oracle Communications Billing and Revenue Management=12.0
Oracle Enterprise Manager For Virtualization=13.2.2
Oracle Enterprise Manager For Virtualization=13.2.3
Oracle Enterprise Manager For Virtualization=13.3.1
Oracle Financial Services Analytical Applications Infrastructure=8.0.2
Oracle Financial Services Analytical Applications Infrastructure=8.0.3
Oracle Financial Services Analytical Applications Infrastructure=8.0.4
Oracle Financial Services Analytical Applications Infrastructure=8.0.5
Oracle Financial Services Analytical Applications Infrastructure=8.0.6
Oracle Financial Services Analytical Applications Infrastructure=8.0.7
Oracle JDeveloper=12.1.3.0.0
Oracle JDeveloper=12.2.1.3.0
Oracle Primavera Unifier>=17.1<=17.12
Oracle Primavera Unifier=16.1
Oracle Primavera Unifier=16.2
Oracle Primavera Unifier=18.8
Oracle Retail Merchandising System=15.0
Oracle Retail Merchandising System=16.0
Oracle WebCenter Portal=12.2.1.3.0
redhat JBoss Enterprise Application Platform=7.2.0
redhat OpenShift Container Platform=3.11
IBM InfoSphere Data Architect<=9.2.1
Remediation
Patch Available
Event History
Jan 2, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Jan 15, 2019
Data Sourced
via Red Hat·07:04 PM
DescriptionSeverityAffected Software
Mar 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID is CVE-2018-14721.
2
What is the severity rating of CVE-2018-14721?
CVE-2018-14721 has a severity rating of medium (5.3).
3
Which software versions are affected by CVE-2018-14721?
Versions up to and exclusive of 2.9.7, 2.7.9.5, 2.8.11.3, 2.9.8-3+deb10u3, 2.9.8-3+deb10u5, 2.12.1-1+deb11u1, and 2.14.0-1 of jackson-databind are affected by CVE-2018-14721.
4
What is the risk associated with CVE-2018-14721?
CVE-2018-14721 allows remote attackers to conduct server-side request forgery and potentially obtain sensitive data.
5
How can I fix CVE-2018-14721?
To fix CVE-2018-14721, update jackson-databind to version 2.9.7 or apply the provided patches from the official GitHub repository.