CVE-2018-14718: Debian Linux
Critical severity, CVSS 9.8. EPSS: 12.7% chance of exploitation in the next 30 days.
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.7.9.5 (fixed in 2.7.9.5); from 2.8.0, before 2.8.11.3 (fixed in 2.8.11.3); from 2.9.0, before 2.9.7 (fixed in 2.9.7)
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Banking Platform: version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
- Oracle Business Process Management Suite: version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
- Oracle Communications Instant Messaging Server: version 10.0.1.3.0 only
- Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only; version 13.3.1 only
- Oracle Financial Services Analytical Applications Infrastructure: version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; version 8.0.7 only
- Oracle Global Lifecycle Management Opatch: before 11.2.0.3.23 (fixed in 11.2.0.3.23); from 12.2.0.1.0, before 12.2.0.1.19 (fixed in 12.2.0.1.19); from 13.9.4.0.0, before 13.9.4.2.1 (fixed in 13.9.4.2.1)
- Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
- Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
- Oracle Jdeveloper: version 12.1.3.0.0 only; version 12.2.1.3.0 only
- Oracle Nosql Database: before 19.3.12 (fixed in 19.3.12); version 19.3.12 only
- Oracle Primavera p6 Enterprise Project Portfolio Management: from 17.7, up to and including 17.12; version 15.1 only; version 15.2 only; version 16.1 only; version 16.2 only; version 18.8 only
- Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
- Oracle Retail Customer Management And Segmentation Foundation: version 17.0 only
- Oracle Retail Merchandising System: version 15.0 only; version 16.0 only
- Oracle Retail Workforce Management Software: version 1.60.9.0.0 only
- Oracle Siebel Engineering - Installer & Deployment: up to and including 19.8
- Oracle Siebel UI Framework: up to and including 19.10
- Oracle Webcenter Portal: version 12.2.1.3.0 only
- Red Hat Openshift Container Platform: from 3.11, before 3.11.153 (fixed in 3.11.153); from 4.6, before 4.6.26 (fixed in 4.6.26); version 3.10 only; from 4.1, before 4.1.18 (fixed in 4.1.18)
Published 2019-01-02. Last modified 2026-10-08.