CVE-2017-15095: Debian Linux
Critical severity, CVSS 9.8. EPSS: 8.4% chance of exploitation in the next 30 days.
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.2 (fixed in 2.6.7.2); from 2.7.0, before 2.7.9.2 (fixed in 2.7.9.2); from 2.8.0, before 2.8.10 (fixed in 2.8.10); version 2.9.0 only
- Netapp Oncommand Balance: affected versions not specified
- Netapp Oncommand Performance Manager: affected versions not specified
- Netapp Oncommand Shift: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Oracle Banking Platform: version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
- Oracle Clusterware: version 12.1.0.2.0 only
- Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
- Oracle Communications Diameter Signaling Router: before 8.3 (fixed in 8.3)
- Oracle Communications Instant Messaging Server: version 10.0.1.2.0 only
- Oracle Database Server: version 12.2.0.1 only; version 18.1 only
- Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only; version 13.3.1 only
- Oracle Financial Services Analytical Applications Infrastructure: version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; version 8.0.7 only
- Oracle Global Lifecycle Management Opatchauto: before 12.2.0.1.14 (fixed in 12.2.0.1.14)
- Oracle Identity Manager: version 11.1.2.3.0 only; version 12.2.1.3.0 only
- Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
- Oracle Primavera Unifier: from 17.1, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
- Oracle Utilities Advanced Spatial And Operational Analytics: version 2.7.0.1 only
- Oracle Webcenter Portal: version 12.2.1.3.0 only
- Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 7.1.0 only
- Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only
- Red Hat Satellite: version 6.4 only
- Red Hat Satellite Capsule: version 6.4 only
Published 2018-02-06. Last modified 2026-10-08.