CVE-2018-11307: Fasterxml Jackson-Databind

Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

Affected products

  • Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.7.9.4 (fixed in 2.7.9.4); from 2.8.0, before 2.8.11.2 (fixed in 2.8.11.2); from 2.9.0, before 2.9.6 (fixed in 2.9.6)
  • Oracle Clusterware: version 12.1.0.2.0 only
  • Oracle Communications Instant Messaging Server: version 10.0.1.2.0 only
  • Oracle Global Lifecycle Management Opatch: before 11.2.0.3.23 (fixed in 11.2.0.3.23); from 12.2.0.1.0, before 12.2.0.1.19 (fixed in 12.2.0.1.19); from 13.9.4.0.0, before 13.9.4.2.1 (fixed in 13.9.4.2.1)
  • Oracle Retail Customer Management And Segmentation Foundation: version 17.0 only
  • Oracle Utilities Advanced Spatial And Operational Analytics: version 2.7.0.1 only
  • Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only

Published 2019-07-09. Last modified 2026-10-08.