CVE-2018-14718: Debian Linux

Critical severity, CVSS 9.8. EPSS: 12.7% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.7.9.5 (fixed in 2.7.9.5); from 2.8.0, before 2.8.11.3 (fixed in 2.8.11.3); from 2.9.0, before 2.9.7 (fixed in 2.9.7)
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Banking Platform: version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
  • Oracle Business Process Management Suite: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
  • Oracle Communications Instant Messaging Server: version 10.0.1.3.0 only
  • Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only; version 13.3.1 only
  • Oracle Financial Services Analytical Applications Infrastructure: version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; version 8.0.7 only
  • Oracle Global Lifecycle Management Opatch: before 11.2.0.3.23 (fixed in 11.2.0.3.23); from 12.2.0.1.0, before 12.2.0.1.19 (fixed in 12.2.0.1.19); from 13.9.4.0.0, before 13.9.4.2.1 (fixed in 13.9.4.2.1)
  • Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Jdeveloper: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Nosql Database: before 19.3.12 (fixed in 19.3.12); version 19.3.12 only
  • Oracle Primavera p6 Enterprise Project Portfolio Management: from 17.7, up to and including 17.12; version 15.1 only; version 15.2 only; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Retail Customer Management And Segmentation Foundation: version 17.0 only
  • Oracle Retail Merchandising System: version 15.0 only; version 16.0 only
  • Oracle Retail Workforce Management Software: version 1.60.9.0.0 only
  • Oracle Siebel Engineering - Installer & Deployment: up to and including 19.8
  • Oracle Siebel UI Framework: up to and including 19.10
  • Oracle Webcenter Portal: version 12.2.1.3.0 only
  • Red Hat Openshift Container Platform: from 3.11, before 3.11.153 (fixed in 3.11.153); from 4.6, before 4.6.26 (fixed in 4.6.26); version 3.10 only; from 4.1, before 4.1.18 (fixed in 4.1.18)

Published 2019-01-02. Last modified 2026-10-08.