CVE-2020-14062: Debian Linux

High severity, CVSS 8.1. EPSS: 8.1% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.9.10.5 (fixed in 2.9.10.5)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Agile Product Lifecycle Management: version 9.3.6 only
  • Oracle Banking Digital Experience: version 18.1 only; version 18.2 only; version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only
  • Oracle Communications Calendar Server: version 8.0.0.4.0 only
  • Oracle Communications Contacts Server: version 8.0.0.5.0 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Element Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Communications Evolved Communications Application Server: version 7.1 only
  • Oracle Communications Session Report Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2

Published 2020-06-14. Last modified 2026-10-08.