CVE-2018-7489: Debian Linux

Critical severity, CVSS 9.8. EPSS: 19.8% chance of exploitation in the next 30 days.

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fasterxml Jackson-Databind: before 2.7.9.3 (fixed in 2.7.9.3); from 2.8.0, before 2.8.11.1 (fixed in 2.8.11.1); from 2.9.0, before 2.9.5 (fixed in 2.9.5)
  • Oracle Communications Billing And Revenue Management: version 7.5 only; version 12.0 only
  • Oracle Communications Instant Messaging Server: version 10.0.1 only
  • Red Hat JBoss Enterprise Application Platform: version 6.4.19 only; version 7.1.2 only

Published 2018-02-26. Last modified 2026-06-17.