EXPOSURES › CVE-2020-9548
CVE-2020-9548
CRITICAL
DETAIL
SourceNVD · cve
Published2020-03-02
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9548 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
NetApp · vendorOracle · vendordebian · vendorfasterxml · vendorWebLogic Server · productactive iq unified manager · productagile product lifecycle management · productautovue for agile product lifecycle management · productbanking digital experience · productbanking platform · productcommunications calendar server · productcommunications contacts server · productcommunications diameter signaling router · productcommunications element manager · productcommunications evolved communications application server · productcommunications instant messaging server · productcommunications network charging and control · productcommunications session report manager · productcommunications session route manager · productdebian linux · productenterprise manager base platform · productglobal lifecycle management opatch · productjackson-databind · productjd edwards enterpriseone orchestrator · productjd edwards enterpriseone tools · productprimavera unifier · productretail merchandising system · productretail sales audit · productretail xstore point of service · product
DESCRIPTION
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
SENTIMENT · TRUSTED SOURCES
synthesis
neutral
+0.00
No sentiment expressed; sources are CVE databases or vendor pages without commentary on Debian's handling.
Neutral; CVE database entry only states the vulnerability without sentiment.
"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core)."
Neutral; CVE database page provides general info, no specific sentiment toward Debian.
Neutral; Vendor security page, no mention of CVE-2020-9548 or Debian.
Neutral; Debian LTS page mentions other patches, no sentiment on CVE-2020-9548.
Neutral; Breach directory unrelated to CVE-2020-9548 or Debian.
Neutral; CVE database page unrelated to CVE-2020-9548 or Debian.
Neutral; GitHub page unrelated to CVE-2020-9548 or Debian.
AFFECTED FEDRAMP PRODUCTS · 11
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |