CVE-2020-11620: Debian Linux

High severity, CVSS 8.1. EPSS: 5.8% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fasterxml Jackson-Databind: from 2.9.0, before 2.9.10.4 (fixed in 2.9.10.4)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Banking Platform: from 2.4.0, up to and including 2.9.0
  • Oracle Communications Contacts Server: version 8.0.0.4.0 only
  • Oracle Communications Evolved Communications Application Server: version 7.1 only
  • Oracle Communications Instant Messaging Server: version 10.0.1.4.0 only
  • Oracle Communications Network Charging And Control: from 12.0.0, up to and including 12.0.3; version 6.0.1 only
  • Oracle Enterprise Manager Base Platform: version 13.3.0.0 only; version 13.4.0.0 only
  • Oracle Global Lifecycle Management Opatch: before 12.2.0.1.20 (fixed in 12.2.0.1.20)
  • Oracle Jd Edwards Enterpriseone Orchestrator: before 9.2.4.2 (fixed in 9.2.4.2)
  • Oracle Jd Edwards Enterpriseone Tools: before 9.2.4.2 (fixed in 9.2.4.2)
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only
  • Oracle Retail Merchandising System: version 15.0 only
  • Oracle Retail Sales Audit: version 14.1 only
  • Oracle Retail Xstore Point Of Service: version 15.0 only; version 16.0 only; version 17.0 only; version 18.0 only; version 19.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2020-04-07. Last modified 2026-10-08.