Back

CVE-2019-16335

CRITICAL

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

Published: Sep 15, 2019 Modified: Jun 17, 2026
CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (39)

Vendor Product Version
fasterxml jackson-databind * ≥ 2.0.0 < 2.6.7.3
fasterxml jackson-databind * ≥ 2.7.0 < 2.8.11.5
fasterxml jackson-databind * ≥ 2.9.0 < 2.9.10
fedoraproject fedora 30
fedoraproject fedora 31
debian debian_linux 8.0
debian debian_linux 9.0
debian debian_linux 10.0
netapp oncommand_api_services -
netapp oncommand_workflow_automation -
netapp steelstore_cloud_integrated_storage -
redhat jboss_enterprise_application_platform 7.2
redhat jboss_enterprise_application_platform 7.3
oracle banking_platform 2.4.0
oracle banking_platform 2.4.1
oracle banking_platform 2.5.0
oracle banking_platform 2.6.0
oracle banking_platform 2.6.1
oracle banking_platform 2.7.0
oracle banking_platform 2.7.1

…and 19 more

GitHub Security Advisory GHSA-85cw-hj65-qqv9

Polymorphic Typing issue in FasterXML jackson-databind

maven com.fasterxml.jackson.core:jackson-databind >= 2.9.0, < 2.9.10 Fixed: 2.9.10
maven com.fasterxml.jackson.core:jackson-databind >= 2.7.0, < 2.8.11.5 Fixed: 2.8.11.5
maven com.fasterxml.jackson.core:jackson-databind < 2.6.7.3 Fixed: 2.6.7.3

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.96%

Top 8% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub