CVE-2017-7525: Debian Linux

Critical severity, CVSS 9.8. EPSS: 37.7% chance of exploitation in the next 30 days.

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: before 2.6.7.1 (fixed in 2.6.7.1); from 2.7.0, before 2.7.9.1 (fixed in 2.7.9.1); from 2.8.0, before 2.8.9 (fixed in 2.8.9); version 2.9.0 only
  • Netapp Oncommand Balance: affected versions not specified
  • Netapp Oncommand Performance Manager: affected versions not specified
  • Netapp Oncommand Shift: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Oracle Banking Platform: version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
  • Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
  • Oracle Communications Communications Policy Management: from 12.0, up to and including 12.5.2
  • Oracle Communications Diameter Signaling Route: before 8.3 (fixed in 8.3)
  • Oracle Communications Instant Messaging Server: version 10.0.1 only; version 10.0.1.2.0 only
  • Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only; version 13.3.1 only
  • Oracle Financial Services Analytical Applications Infrastructure: version 8.0.2.0.0 only; version 8.0.3.0.0 only; version 8.0.4.0.0 only; version 8.0.5.0.0 only; version 8.0.6.0.0 only; version 8.0.7.0.0 only
  • Oracle Global Lifecycle Management Opatchauto: before 12.2.0.1.14 (fixed in 12.2.0.1.14)
  • Oracle Primavera Unifier: from 17.1, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Utilities Advanced Spatial And Operational Analytics: version 2.7.0.1 only
  • Oracle Webcenter Portal: version 12.2.1.3.0 only
  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 7.0 only; version 7.1 only
  • Red Hat Openshift Container Platform: version 4.1 only; version 3.11 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-02-06. Last modified 2026-10-08.