CVE-2019-16942: Debian Linux
Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.8.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10.1 (fixed in 2.9.10.1)
- Fedoraproject Fedora: version 30 only; version 31 only
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Oncommand API Services: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Service Level Manager: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Banking Platform: version 2.4.0 only; version 2.4.1 only; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; …
- Oracle Communications Billing And Revenue Management: version 7.5.0.23.0 only; version 12.0.0.3.0 only
- Oracle Communications Calendar Server: version 8.0.0.2.0 only; version 8.0.0.3.0 only
- Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
- Oracle Communications Evolved Communications Application Server: version 7.1 only
- Oracle Database Server: version 12.2.0.1 only; version 18c only; version 19c only
- Oracle Global Lifecycle Management NextGen Oui Framework: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 13.9.4.2.2 only
- Oracle Goldengate Application Adapters: version 19.1.0.0.0 only
- Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
- Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
- Oracle Primavera Gateway: from 17.12.0, up to and including 17.12.6; from 18.8.0, up to and including 18.8.8; version 19.12.0 only
- Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only
- Oracle Retail Merchandising System: version 15.0.3 only; version 16.0.2 only; version 16.0.3 only
- Oracle Retail Sales Audit: version 14.1 only
- Oracle Siebel Engineering - Installer & Deployment: up to and including 2.20.5
- Oracle Siebel UI Framework: up to and including 20.5; version 20.6 only
- Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- and 3 more
Published 2019-10-01. Last modified 2026-10-08.