CVE-2018-19361: Debian Linux

Critical severity, CVSS 9.8. EPSS: 10.6% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: from 2.6.0, up to and including 2.6.7.2; from 2.7.0, before 2.7.9.5 (fixed in 2.7.9.5); from 2.8.0, before 2.8.11.3 (fixed in 2.8.11.3); from 2.9.0, before 2.9.8 (fixed in 2.9.8)
  • Oracle Business Process Management Suite: version 12.1.3.0.0 only; version 12.2.1.3.0 only
  • Oracle Primavera p6 Enterprise Project Portfolio Management: from 17.7, up to and including 17.12; version 15.1 only; version 15.2 only; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only
  • Oracle Retail Workforce Management Software: version 1.60.9.0.0 only
  • Oracle Webcenter Portal: version 12.2.1.3.0 only
  • Red Hat Automation Manager: version 7.3.1 only
  • Red Hat Decision Manager: version 7.3.1 only
  • Red Hat JBoss Bpm Suite: version 6.4.11 only
  • Red Hat JBoss Brms: version 6.4.10 only
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2019-01-02. Last modified 2026-06-17.