VYPR
Critical severity10.0OSV Advisory· Published Jan 2, 2019· Updated Jun 17, 2026

CVE-2018-14721

CVE-2018-14721

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.9.0, < 2.9.72.9.7
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.8.0, < 2.8.11.32.8.11.3
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.7.0, < 2.7.9.52.7.9.5

Affected products

42
  • 2.2.0c, jackson-databind-2.0.0, jackson-databind-2.0.0-RC1, …+ 10 more
    • (no CPE)range: 2.2.0c, jackson-databind-2.0.0, jackson-databind-2.0.0-RC1, …
    • cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*range: >=2.6.0,<2.6.7.2
    • cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr1:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr2:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr3:*:*:*:*:*:*
    • cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr4:*:*:*:*:*:*
  • cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.3.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.2:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.1,<=17.12
    • cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:retail_merchandising_system:16.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • osv-coords3 versions
    < 4.0.1-r1+ 2 more
    • (no CPE)range: < 4.0.1-r1
    • (no CPE)range: < 4.0.1-r1
    • (no CPE)range: >= 2.9.0, < 2.9.7

Patches

Vulnerability mechanics

References

36

News mentions

0

No linked articles in our index yet.