CVE-2019-17267: Debian Linux

Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10 (fixed in 2.9.10)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Customer Management And Segmentation Foundation: before 18.0 (fixed in 18.0)
  • Oracle Goldengate Application Adapters: version 19.1.0.0.0 only
  • Oracle Retail Customer Management And Segmentation Foundation: version 17.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2 only; version 7.3 only

Published 2019-10-07. Last modified 2026-10-07.