Disclosure summary
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Source-reported weakness categories
CWE-502
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2018-11307
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| fasterxml | jackson-databind | * {"versionStartIncluding":"2.9.0","versionEndExcluding":"2.9.6"} |
| redhat | openshift_container_platform | 3.11 |
| redhat | openshift_container_platform | 4.1 |
| oracle | clusterware | 12.1.0.2.0 |
| oracle | communications_instant_messaging_server | 10.0.1.2.0 |
| oracle | global_lifecycle_management_opatch | * {"versionStartIncluding":"13.9.4.0.0","versionEndExcluding":"13.9.4.2.1"} |
| oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
| oracle | utilities_advanced_spatial_and_operational_analytics | 2.7.0.1 |
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- github.com — Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- medium.com — Third Party Advisory
- nvd.nist.gov — Third Party Advisory, US Government Resource
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- github.com — Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- lists.apache.org — Mailing List, Third Party Advisory
- medium.com — Third Party Advisory
- nvd.nist.gov — Third Party Advisory, US Government Resource
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
PUBLISHED 2019-07-09T12:15:12-04:00
MODIFIED 2026-10-08T17:17:07-04:00
INGESTED 2026-10-10T20:50:18-04:00