CVE-2020-14060: Fasterxml Jackson-Databind
High severity, CVSS 8.1. EPSS: 8.6% chance of exploitation in the next 30 days.
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Affected products
- Fasterxml Jackson-Databind: from 2.0.0, before 2.9.10.5 (fixed in 2.9.10.5)
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Agile Product Lifecycle Management: version 9.3.6 only
- Oracle Banking Digital Experience: version 18.1 only; version 18.2 only; version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only
- Oracle Communications Calendar Server: version 8.0.0.4.0 only
- Oracle Communications Contacts Server: version 8.0.0.5.0 only
- Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
- Oracle Communications Element Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications Evolved Communications Application Server: version 7.1 only
- Oracle Communications Session Report Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
Published 2020-06-14. Last modified 2026-10-08.