Description
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Published: 2018-01-10
Score: 9.8 Critical
EPSS: 79.8% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-4114-1 jackson-databind security update
Github GHSA Github GHSA GHSA-rfx6-vp9g-rh7v jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass
History

Wed, 27 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 Aug 2024 05:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7

Subscriptions

Debian Debian Linux
Fasterxml Jackson-databind
Netapp E-series Santricity Os Controller E-series Santricity Web Services Proxy Oncommand Shift Snapcenter
Redhat Enterprise Linux Server Jboss Bpms Jboss Enterprise Application Platform Jboss Enterprise Brms Platform Jboss Fuse Jboss Operations Network Openshift Openshift Container Platform Rhel Software Collections
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-27T20:31:49.308Z

Reserved: 2017-12-10T00:00:00.000Z

Link: CVE-2017-17485

cve-icon Vulnrichment

Updated: 2024-08-05T20:51:32.239Z

cve-icon NVD

Status : Modified

Published: 2018-01-10T18:29:01.167

Modified: 2025-08-27T21:15:33.800

Link: CVE-2017-17485

cve-icon Redhat

Severity : Important

Publid Date: 2017-12-12T00:00:00Z

Links: CVE-2017-17485 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses