CVE-2019-17531: Debian Linux
Critical severity, CVSS 9.8. EPSS: 5.4% chance of exploitation in the next 30 days.
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.
Affected products
- Debian Debian Linux: version 8.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10.1 (fixed in 2.9.10.1)
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Banking Platform: version 2.4.0 only; version 2.4.1 only; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; …
- Oracle Communications Billing And Revenue Management: version 7.5.0.23.0 only; version 12.0.0.3.0 only
- Oracle Communications Calendar Server: version 8.0.0.2.0 only; version 8.0.0.3.0 only
- Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
- Oracle Communications Evolved Communications Application Server: version 7.1 only
- Oracle Global Lifecycle Management NextGen Oui Framework: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 13.9.4.2.2 only
- Oracle Goldengate Application Adapters: version 19.1.0.0.0 only
- Oracle Jd Edwards Enterpriseone Orchestrator: version 9.2 only
- Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
- Oracle Primavera Gateway: from 17.7, up to and including 17.12.6; from 18.8.0, up to and including 18.8.8; version 16.1 only; version 16.2 only; version 19.12.0 only
- Oracle Retail Merchandising System: version 15.0.3 only; version 16.0.2 only; version 16.0.3 only
- Oracle Retail Sales Audit: version 14.1 only
- Oracle Siebel Engineering - Installer & Deployment: up to and including 2.20.5
- Oracle Trace File Analyzer: version 12.2.0.1 only; version 18c only; version 19c only
- Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Webcenter Sites: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.2 only; version 7.3 only
Published 2019-10-12. Last modified 2026-10-08.