CVE-2017-17485: Debian Linux

Critical severity, CVSS 9.8. EPSS: 49.7% chance of exploitation in the next 30 days.

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.7.9.2 (fixed in 2.7.9.2); from 2.8.0, before 2.8.11 (fixed in 2.8.11); from 2.9.0, before 2.9.4 (fixed in 2.9.4)
  • Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
  • Netapp E-Series Santricity Web Services Proxy: affected versions not specified
  • Netapp Oncommand Shift: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 7.1 only
  • Red Hat Openshift Container Platform: version 4.1 only; version 3.11 only

Published 2018-01-10. Last modified 2026-06-17.