CVE-2018-14721: Debian Linux

Critical severity, CVSS 10.0. EPSS: 10.5% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: from 2.6.0, before 2.6.7.2 (fixed in 2.6.7.2); from 2.7.0, before 2.7.9.5 (fixed in 2.7.9.5); from 2.8.0, before 2.8.11.3 (fixed in 2.8.11.3); from 2.9.0, before 2.9.7 (fixed in 2.9.7); version 2.7.0 only; version 2.8.0 only; …
  • Oracle Banking Platform: version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
  • Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
  • Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only; version 13.3.1 only
  • Oracle Financial Services Analytical Applications Infrastructure: version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; version 8.0.7 only
  • Oracle Jdeveloper: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Primavera Unifier: from 17.1, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Retail Merchandising System: version 15.0 only; version 16.0 only
  • Oracle Webcenter Portal: version 12.2.1.3.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2.0 only
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2019-01-02. Last modified 2026-06-17.