CVE-2020-36518: Debian Linux
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only; version 11.0 only
- Fasterxml Jackson-Databind: before 2.12.6.1 (fixed in 2.12.6.1); from 2.13.0, before 2.13.2.1 (fixed in 2.13.2.1)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Cloud Insights Acquisition Unit: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Snap Creator Framework: affected versions not specified
- Oracle Big Data Spatial And Graph: before 23.1 (fixed in 23.1)
- Oracle Coherence: version 14.1.1.0.0 only
- Oracle Commerce Platform: version 11.3.0 only; version 11.3.1 only; version 11.3.2 only
- Oracle Communications Billing And Revenue Management: from 12.0.0.4.0, up to and including 12.0.0.6.0
- Oracle Communications Cloud Native Core Binding Support Function: version 22.1.3 only
- Oracle Communications Cloud Native Core Console: version 1.9.0 only
- Oracle Communications Cloud Native Core Network Repository Function: version 22.1.2 only; version 22.2.0 only
- Oracle Communications Cloud Native Core Network Slice Selection Function: version 22.1.0 only; version 22.1.1 only
- Oracle Communications Cloud Native Core Security Edge Protection Proxy: version 22.1.1 only
- Oracle Communications Cloud Native Core Service Communication Proxy: version 22.2.0 only
- Oracle Communications Cloud Native Core Unified Data Repository: version 22.2.0 only
- Oracle Financial Services Analytical Applications Infrastructure: from 8.0.7, up to and including 8.1.0.0; version 8.1.1.0 only; version 8.1.2.0 only; version 8.1.2.1 only
- Oracle Financial Services Behavior Detection Platform: from 8.1.1.0, up to and including 8.1.2.1; version 8.0.7.0.0 only; version 8.0.8 only
- Oracle Financial Services Crime And Compliance Management Studio: version 8.0.8.2.0 only; version 8.0.8.3.0 only
- Oracle Financial Services Enterprise Case Management: from 8.1.1.0, up to and including 8.1.2.1; version 8.0.7.1 only; version 8.0.7.2 only; version 8.0.8.0 only; version 8.0.8.1 only
- Oracle Financial Services Trade-Based Anti Money Laundering: version 8.0.7 only; version 8.0.8 only
- Oracle Global Lifecycle Management NextGen Oui Framework: before 13.9.4.2.2 (fixed in 13.9.4.2.2); version 13.9.4.2.2 only
- Oracle Global Lifecycle Management Opatch: before 12.2.0.1.30 (fixed in 12.2.0.1.30)
- and 11 more
Published 2022-03-11. Last modified 2026-06-17.