FlawAtlas
Search the atlas
CVE-2018-12023 High

Deserialization of Untrusted Data

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

Exploit probability 8.9%
Published June 15, 2020
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Maven com.fasterxml.jackson.core:jackson-databind

38 explicit affected versions

Unknown Unknown

33 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2018-12023

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

View original source
Open Source Vulnerabilities GHSA-6wqp-v4v6-c87c

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

View original source

05 / REFERENCES

Further evidence