Skip to content
COOEY

EXPOSURES › CVE-2020-9546

CVE-2020-9546

CRITICAL
DETAIL
SourceNVD · cve Published2020-03-02 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9546 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No coverage of CVE-2020-9546 vendor response or handling found in sources; sources are unrelated to the event.
cooey ↗ neutral +0.00
Neutral; source only lists CVE details without vendor response or handling.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."
app.opencve.io ↗ neutral +0.00
Neutral; source is a CVE database listing unrelated to vendor handling.
"CVE-2020-35728 5 Debian , Fasterxml , Netapp and 2 more 42 Debian Linux , Jackson-databind , Service Level Manager and 39 more 2026-08-25 8.1 High FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.j"
haveibeenpwned.com ↗ neutral +0.00
Neutral; source is unrelated data breach report.
"In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram."
haveibeenpwned.com ↗ neutral +0.00
Neutral; source is unrelated data breach report.
"In August 2026, clothing retailer Carhartt was the target of a ShinyHunters 'pay or leak' extortion campaign ."
The Hacker News ↗ neutral +0.00
Neutral; source is unrelated Oracle WebLogic flaw report.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
www.hipaajournal.com ↗ neutral +0.00
Neutral; source is unrelated HIPAA breach report.
"Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit"
openclassactions.com ↗ neutral +0.00
Neutral; source is unrelated data breach settlement report.
"SitusAMC $5.3M Data Breach Settlement — $75 or Up to $5,000"
AFFECTED FEDRAMP PRODUCTS · 11
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Cloud Insights
NetApp
In Process
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized