A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_enterprise_application_platform | Redhat | 7.2.0 (including) | 7.2.0 (including) |
Red Hat Fuse 7.8.0 | RedHat | codehaus | * |
Red Hat JBoss EAP 7.2 | RedHat | codehaus | * |
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap | * |