CVE-2020-14061: Debian Linux
High severity, CVSS 8.1. EPSS: 4.5% chance of exploitation in the next 30 days.
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).
Affected products
- Debian Debian Linux: version 8.0 only
- Fasterxml Jackson-Databind: from 2.9.0, before 2.9.10.5 (fixed in 2.9.10.5)
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle Agile Product Lifecycle Management: version 9.3.6 only
- Oracle Autovue For Agile Product Lifecycle Management: version 21.0.2 only
- Oracle Banking Digital Experience: version 18.1 only; version 18.2 only; version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only
- Oracle Communications Calendar Server: version 8.0.0.4.0 only
- Oracle Communications Contacts Server: version 8.0.0.5.0 only
- Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
- Oracle Communications Element Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications Evolved Communications Application Server: version 7.1 only
- Oracle Communications Instant Messaging Server: version 10.0.1.4.0 only
- Oracle Communications Session Report Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
Published 2020-06-14. Last modified 2026-08-25.