CVE-2018-11307
CRITICALCVSS 9.8/10EPSS 5.68%
Last modified
CVE-2018-11307 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. EPSS estimates a 5.68% chance of exploitation in the next 30 days.
Description
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Databind | >= 2.0.0, < 2.6.7.3 |
| Fasterxml | Jackson-Databind | >= 2.7.0, < 2.7.9.4 |
| Fasterxml | Jackson-Databind | >= 2.8.0, < 2.8.11.2 |
| Fasterxml | Jackson-Databind | >= 2.9.0, < 2.9.6 |
| Redhat | Openshift Container Platform | 3.11 |
| Redhat | Openshift Container Platform | 4.1 |
| Oracle | Clusterware | 12.1.0.2.0 |
| Oracle | Communications Instant Messaging Server | 10.0.1.2.0 |
| Oracle | Global Lifecycle Management Opatch | < 11.2.0.3.23 |
| Oracle | Global Lifecycle Management Opatch | >= 12.2.0.1.0, < 12.2.0.1.19 |
| Oracle | Global Lifecycle Management Opatch | >= 13.9.4.0.0, < 13.9.4.2.1 |
| Oracle | Retail Customer Management And Segmentation Foundation | 17.0 |
| Oracle | Utilities Advanced Spatial And Operational Analytics | 2.7.0.1 |
References
- https://access.redhat.com/errata/RHSA-2019:0782Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1822Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1823Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3002Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4037Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2032Third Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EMailing List, Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7525Third Party Advisory, US Government Resource
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0782Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1822Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1823Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3002Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4037Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2032Third Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EMailing List, Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7525Third Party Advisory, US Government Resource
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11307?
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
How severe is CVE-2018-11307?
CVE-2018-11307 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 5.68% probability of exploitation in the next 30 days.
How do I fix CVE-2018-11307?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2018-11307?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
