FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Cloud_backup | Netapp | - (including) | - (including) | 
| Service_level_manager | Netapp | - (including) | - (including) | 
| OpenShift Logging 5.0 | RedHat | openshift-logging/elasticsearch6-rhel8:v5.0.3-1 | * | 
| Red Hat OpenShift Container Platform 4.6 | RedHat | openshift4/ose-logging-elasticsearch6:v4.6.0-202104161407.p0 | * | 
| Jackson-databind | Ubuntu | bionic | * | 
| Jackson-databind | Ubuntu | focal | * | 
| Jackson-databind | Ubuntu | groovy | * | 
| Jackson-databind | Ubuntu | hirsute | * | 
| Jackson-databind | Ubuntu | impish | * | 
| Jackson-databind | Ubuntu | kinetic | * | 
| Jackson-databind | Ubuntu | lunar | * | 
| Jackson-databind | Ubuntu | mantic | * | 
| Jackson-databind | Ubuntu | oracular | * | 
| Jackson-databind | Ubuntu | trusty | * | 
| Jackson-databind | Ubuntu | trusty/esm | * | 
| Jackson-databind | Ubuntu | xenial | * |