CVE-2019-16942: Debian Linux

Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.8.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10.1 (fixed in 2.9.10.1)
  • Fedoraproject Fedora: version 30 only; version 31 only
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Banking Platform: version 2.4.0 only; version 2.4.1 only; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; …
  • Oracle Communications Billing And Revenue Management: version 7.5.0.23.0 only; version 12.0.0.3.0 only
  • Oracle Communications Calendar Server: version 8.0.0.2.0 only; version 8.0.0.3.0 only
  • Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
  • Oracle Communications Evolved Communications Application Server: version 7.1 only
  • Oracle Database Server: version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Global Lifecycle Management NextGen Oui Framework: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 13.9.4.2.2 only
  • Oracle Goldengate Application Adapters: version 19.1.0.0.0 only
  • Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Primavera Gateway: from 17.12.0, up to and including 17.12.6; from 18.8.0, up to and including 18.8.8; version 19.12.0 only
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only
  • Oracle Retail Merchandising System: version 15.0.3 only; version 16.0.2 only; version 16.0.3 only
  • Oracle Retail Sales Audit: version 14.1 only
  • Oracle Siebel Engineering - Installer & Deployment: up to and including 2.20.5
  • Oracle Siebel UI Framework: up to and including 20.5; version 20.6 only
  • Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • and 3 more

Published 2019-10-01. Last modified 2026-10-08.