Back
CVE-2019-16335
CRITICAL
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
Published: Sep 15, 2019
Modified: Jun 17, 2026
CWE-502
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (39)
| Vendor | Product | Version |
|---|---|---|
| fasterxml | jackson-databind | * ≥ 2.0.0 < 2.6.7.3 |
| fasterxml | jackson-databind | * ≥ 2.7.0 < 2.8.11.5 |
| fasterxml | jackson-databind | * ≥ 2.9.0 < 2.9.10 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| netapp | oncommand_api_services | - |
| netapp | oncommand_workflow_automation | - |
| netapp | steelstore_cloud_integrated_storage | - |
| redhat | jboss_enterprise_application_platform | 7.2 |
| redhat | jboss_enterprise_application_platform | 7.3 |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.4.1 |
| oracle | banking_platform | 2.5.0 |
| oracle | banking_platform | 2.6.0 |
| oracle | banking_platform | 2.6.1 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
…and 19 more
GitHub Security Advisory GHSA-85cw-hj65-qqv9
Polymorphic Typing issue in FasterXML jackson-databind
maven
com.fasterxml.jackson.core:jackson-databind
>= 2.9.0, < 2.9.10
Fixed: 2.9.10
maven
com.fasterxml.jackson.core:jackson-databind
>= 2.7.0, < 2.8.11.5
Fixed: 2.8.11.5
maven
com.fasterxml.jackson.core:jackson-databind
< 2.6.7.3
Fixed: 2.6.7.3
References (64)
- https://access.redhat.com/errata/RHSA-2019:3200 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0159 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0729 Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2449 Patch, Third Party Advisory
- https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.96%
Top 8% most likely to be exploited
Threat Score
40.7 / 100
Data Sources
NVD
EPSS
GitHub