No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2153-1 | jackson-databind security update |
Github GHSA |
GHSA-fqwf-pjwf-7vqv | jackson-databind mishandles the interaction between serialization gadgets and typing |
Ubuntu USN |
USN-4813-1 | Jackson Databind vulnerabilities |
Thu, 01 May 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fasterxml:jackson-databind:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_router:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_policy_administration_j2ee:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* |
|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Subscriptions
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-27T20:32:51.171Z
Reserved: 2020-03-18T00:00:00.000Z
Link: CVE-2020-10673
Updated: 2024-08-04T11:06:10.672Z
Status : Modified
Published: 2020-03-18T22:15:12.407
Modified: 2024-11-21T04:55:49.360
Link: CVE-2020-10673
OpenCVE Enrichment
No data.
-
CWE-502
Deserialization of Untrusted Data
-
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- NVD-CWE-Other
Debian DLA
Github GHSA
Ubuntu USN