CVE-2018-1000873
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
Published:Oct 24, 2018
Last Modified:Nov 21, 2024
EPS:Dec 20, 2018
EPSS Score:0.026
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Fasterxml
Product
Jackson-modules-java8
Fasterxml
Jackson-modules-java8
Vendor
Netapp
Product
Active Iq Unified Manager
Netapp
Active Iq Unified Manager
Vendor
Oracle
Product
Clusterware
Oracle
Clusterware
Vendor
Oracle
Product
Database Server
Oracle
Database Server
Vendor
Oracle
Product
Global Lifecycle Management Opatch
Oracle
Global Lifecycle Management Opatch
Vendor
Oracle
Product
Nosql Database
Oracle
Nosql Database
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
