CVE-2017-15095

high-risk
Published 2018-02-06

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Do I need to act?

~
8.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: fab5c3877f7b8ae28a8e3a14d805bc9dcc8c153d, 9e170e1a28221cf273e8a63e01f1731a9fcd11bc, 0b6e589c1c0ee20854ac0efeafacbf2782fc9f1c
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Vendors

68
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 10/34 · Low
Exposure 26/34 · High