Vulnerabilities > Fasterxml

DATE CVE VULNERABILITY TITLE RISK
2021-01-07 CVE-2020-36183 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
network
fasterxml CWE-502
6.8
2021-01-07 CVE-2020-36182 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
network
fasterxml CWE-502
6.8
2021-01-07 CVE-2020-36180 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
network
fasterxml CWE-502
6.8
2021-01-07 CVE-2020-36179 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36189 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36188 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36187 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36186 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36185 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
network
fasterxml CWE-502
6.8
2021-01-06 CVE-2020-36184 Deserialization of Untrusted Data vulnerability in Fasterxml Jackson-Databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
network
fasterxml CWE-502
6.8