EXPOSURES › CVE-2020-9546
CVE-2020-9546
CRITICAL
DETAIL
SourceNVD · cve
Published2020-03-02
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9546 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
NetApp · vendorOracle · vendordebian · vendorfasterxml · vendorWebLogic Server · productactive iq unified manager · productagile product lifecycle management · productautovue for agile product lifecycle management · productbanking digital experience · productbanking platform · productcommunications calendar server · productcommunications contacts server · productcommunications diameter signaling router · productcommunications element manager · productcommunications evolved communications application server · productcommunications instant messaging server · productcommunications network charging and control · productcommunications session report manager · productcommunications session route manager · productdebian linux · productenterprise manager base platform · productfinancial services analytical applications infrastructure · productfinancial services institutional performance analytics · productfinancial services price creation and discovery · productfinancial services retail customer analytics · productglobal lifecycle management opatch · productinsurance policy administration j2ee · productjackson-databind · productjd edwards enterpriseone orchestrator · productjd edwards enterpriseone tools · productprimavera unifier · productretail merchandising system · productretail sales audit · productretail service backbone · productretail xstore point of service · product
DESCRIPTION
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
SENTIMENT · TRUSTED SOURCES
synthesis
neutral
+0.00
No coverage of CVE-2020-9546 vendor response or handling found in sources; sources are unrelated to the event.
Neutral; source only lists CVE details without vendor response or handling.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."
Neutral; source is a CVE database listing unrelated to vendor handling.
"CVE-2020-35728 5 Debian , Fasterxml , Netapp and 2 more 42 Debian Linux , Jackson-databind , Service Level Manager and 39 more 2026-08-25 8.1 High FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.j"
Neutral; source is unrelated data breach report.
"In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram."
Neutral; source is unrelated data breach report.
"In August 2026, clothing retailer Carhartt was the target of a ShinyHunters 'pay or leak' extortion campaign ."
Neutral; source is unrelated Oracle WebLogic flaw report.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
Neutral; source is unrelated HIPAA breach report.
"Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit"
Neutral; source is unrelated data breach settlement report.
"SitusAMC $5.3M Data Breach Settlement — $75 or Up to $5,000"
AFFECTED FEDRAMP PRODUCTS · 11
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |