CVE-2020-14195: Debian Linux

High severity, CVSS 8.1. EPSS: 4.5% chance of exploitation in the next 30 days.

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fasterxml Jackson-Databind: from 2.9.0, before 2.9.10.5 (fixed in 2.9.10.5)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Agile Product Lifecycle Management: version 9.3.6 only
  • Oracle Banking Digital Experience: version 18.1 only; version 18.2 only; version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only
  • Oracle Communications Calendar Server: version 8.0.0.4.0 only
  • Oracle Communications Contacts Server: version 8.0.0.5.0 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Element Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Communications Evolved Communications Application Server: version 7.1 only
  • Oracle Communications Instant Messaging Server: version 10.0.1.4.0 only
  • Oracle Communications Session Report Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2

Published 2020-06-16. Last modified 2026-10-08.