AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2017-7525.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.8CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Source-reported weakness categories

CWE-184, CWE-502

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2017-7525

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
fasterxmljackson-databind* {"versionStartIncluding":"2.8.0","versionEndExcluding":"2.8.9"}
fasterxmljackson-databind2.9.0
fasterxmljackson-databind2.9.0
debiandebian_linux8.0
debiandebian_linux9.0
netapponcommand_balance-
netapponcommand_performance_manager-
netapponcommand_performance_manager-
netapponcommand_shift-
netappsnapcenter-
redhatopenshift_container_platform4.1
redhatvirtualization4.0
redhatvirtualization_host4.0
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
redhatjboss_enterprise_application_platform7.0
redhatjboss_enterprise_application_platform7.1
redhatopenshift_container_platform3.11
oraclebanking_platform2.5.0
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclecommunications_billing_and_revenue_management7.5
oraclecommunications_billing_and_revenue_management12.0
oraclecommunications_communications_policy_management* {"versionStartIncluding":"12.0","versionEndIncluding":"12.5.2"}
oraclecommunications_diameter_signaling_route* {"versionEndExcluding":"8.3"}
oraclecommunications_instant_messaging_server10.0.1
oraclecommunications_instant_messaging_server10.0.1.2.0
oracleenterprise_manager_for_virtualization13.2.2
oracleenterprise_manager_for_virtualization13.2.3
oracleenterprise_manager_for_virtualization13.3.1
oraclefinancial_services_analytical_applications_infrastructure8.0.2.0.0
oraclefinancial_services_analytical_applications_infrastructure8.0.3.0.0
oraclefinancial_services_analytical_applications_infrastructure8.0.4.0.0
oraclefinancial_services_analytical_applications_infrastructure8.0.5.0.0
oraclefinancial_services_analytical_applications_infrastructure8.0.6.0.0
oraclefinancial_services_analytical_applications_infrastructure8.0.7.0.0
oracleglobal_lifecycle_management_opatchauto* {"versionEndExcluding":"12.2.0.1.14"}
oracleprimavera_unifier* {"versionStartIncluding":"17.1","versionEndIncluding":"17.12"}
oracleprimavera_unifier16.1
oracleprimavera_unifier16.2
oracleprimavera_unifier18.8
oracleutilities_advanced_spatial_and_operational_analytics2.7.0.1
oraclewebcenter_portal12.2.1.3.0

Original records & references

PUBLISHED 2018-02-06T10:29:00-05:00
MODIFIED 2026-10-08T18:16:41-04:00
INGESTED 2026-10-10T20:50:18-04:00