CVE-2019-16943: Debian Linux

Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10.1 (fixed in 2.9.10.1)
  • Fedoraproject Fedora: version 30 only; version 31 only
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Banking Platform: version 2.4.0 only; version 2.4.1 only; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; …
  • Oracle Communications Billing And Revenue Management: version 7.5.0.23.0 only; version 12.0.0.3.0 only
  • Oracle Communications Calendar Server: version 8.0.0.2.0 only; version 8.0.0.3.0 only
  • Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
  • Oracle Communications Evolved Communications Application Server: version 7.1 only
  • Oracle Global Lifecycle Management NextGen Oui Framework: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 13.9.4.2.2 only
  • Oracle Goldengate Application Adapters: version 19.1.0.0.0 only
  • Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Primavera Gateway: from 17.7, up to and including 17.12.6; from 18.8.0, up to and including 18.8.8; version 16.1 only; version 16.2 only; version 19.12.0 only
  • Oracle Retail Merchandising System: version 15.0.3 only; version 16.0.2 only; version 16.0.3 only
  • Oracle Retail Sales Audit: version 14.1 only
  • Oracle Siebel Engineering - Installer & Deployment: up to and including 2.20.5
  • Oracle Trace File Analyzer: version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • and 1 more

Published 2019-10-01. Last modified 2026-10-07.