FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
History

Mon, 23 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Netapp steelstore Cloud Integrated Storage
Oracle banking Digital Experience
Oracle communications Calendar Server
Oracle communications Diameter Signaling Router
Oracle enterprise Manager Base Platform
Oracle financial Services Analytical Applications Infrastructure
Oracle financial Services Institutional Performance Analytics
Oracle financial Services Price Creation And Discovery
Oracle financial Services Retail Customer Analytics
Oracle global Lifecycle Management Opatch
Oracle insurance Policy Administration J2ee
Oracle retail Sales Audit
Oracle weblogic Server
CPEs cpe:2.3:a:fasterxml:jackson-databind:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_calendar_server:8.0.0.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_diameter_signaling_router:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_route_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_retail_customer_analytics:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_sales_audit:14.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_service_backbone:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Vendors & Products Netapp steelstore Cloud Integrated Storage
Oracle banking Digital Experience
Oracle communications Calendar Server
Oracle communications Diameter Signaling Router
Oracle enterprise Manager Base Platform
Oracle financial Services Analytical Applications Infrastructure
Oracle financial Services Institutional Performance Analytics
Oracle financial Services Price Creation And Discovery
Oracle financial Services Retail Customer Analytics
Oracle global Lifecycle Management Opatch
Oracle insurance Policy Administration J2ee
Oracle retail Sales Audit
Oracle weblogic Server
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-06T22:29:19.000Z

Updated: 2024-08-04T17:23:09.306Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2020-36181

cve-icon Vulnrichment

Updated: 2024-08-04T17:23:09.306Z

cve-icon NVD

Status : Modified

Published: 2021-01-06T23:15:12.957

Modified: 2024-11-21T05:28:55.090

Link: CVE-2020-36181

cve-icon Redhat

Severity : Important

Publid Date: 2020-12-31T00:00:00Z

Links: CVE-2020-36181 - Bugzilla