CVE-2019-16942 - CVE House
Back to Database
Status published Critical CVE-2019-16942

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0...

Vulnerability Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-16942

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jackson-databind, debian linux, fedora, jboss enterprise application platform, active iq unified manager, oncommand api services, oncommand workflow automation, service level manager, steelstore cloud integrated storage, banking platform, communications billing and revenue management, communications calendar server, communications cloud native core network slice selection function, communications evolved communications application server, database server, global lifecycle management nextgen oui framework, goldengate application adapters, jd edwards enterpriseone orchestrator, jd edwards enterpriseone tools, primavera gateway, primavera unifier, retail merchandising system, retail sales audit, siebel engineering - installer \& deployment, siebel ui framework, webcenter portal, webcenter sites, weblogic server
Vulnerable Versions:
2.0.0, 2.8.0, 2.9.0, 8.0, 9.0, 10.0, 30, 31, 7.2.0, 7.3, 9.5, 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 7.5.0.23.0, 12.0.0.3.0, 8.0.0.2.0, 8.0.0.3.0, 1.2.1, 7.1, 12.2.0.1, 18c, 19c, 12.2.1.3.0, 12.2.1.4.0, 13.9.4.2.2, 19.1.0.0.0, 9.2, 17.12.0, 18.8.0, 19.12.0, 17.7, 16.1, 16.2, 18.8, 19.12, 15.0.3, 16.0.2, 16.0.3, 14.1, 0, 20.6

Timeline

Official Publish: October 1st, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.