Disclosure summary
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Source-reported weakness categories
CWE-502
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2019-16942
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| fasterxml | jackson-databind | * {"versionStartIncluding":"2.9.0","versionEndExcluding":"2.9.10.1"} |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| redhat | jboss_enterprise_application_platform | 7.2.0 |
| redhat | jboss_enterprise_application_platform | 7.3 |
| netapp | active_iq_unified_manager | * {"versionStartIncluding":"7.3"} |
| netapp | active_iq_unified_manager | * {"versionStartIncluding":"7.3"} |
| netapp | active_iq_unified_manager | * {"versionStartIncluding":"9.5"} |
| netapp | oncommand_api_services | - |
| netapp | oncommand_workflow_automation | - |
| netapp | service_level_manager | - |
| netapp | steelstore_cloud_integrated_storage | - |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.4.1 |
| oracle | banking_platform | 2.5.0 |
| oracle | banking_platform | 2.6.0 |
| oracle | banking_platform | 2.6.1 |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | communications_billing_and_revenue_management | 7.5.0.23.0 |
| oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
| oracle | communications_calendar_server | 8.0.0.2.0 |
| oracle | communications_calendar_server | 8.0.0.3.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | 1.2.1 |
| oracle | communications_evolved_communications_application_server | 7.1 |
| oracle | database_server | 12.2.0.1 |
| oracle | database_server | 18c |
| oracle | database_server | 19c |
| oracle | global_lifecycle_management_nextgen_oui_framework | 12.2.1.3.0 |
| oracle | global_lifecycle_management_nextgen_oui_framework | 12.2.1.4.0 |
| oracle | global_lifecycle_management_nextgen_oui_framework | 13.9.4.2.2 |
| oracle | goldengate_application_adapters | 19.1.0.0.0 |
| oracle | jd_edwards_enterpriseone_orchestrator | 9.2 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | primavera_gateway | * {"versionStartIncluding":"18.8.0","versionEndIncluding":"18.8.8"} |
| oracle | primavera_gateway | 19.12.0 |
| oracle | primavera_unifier | * {"versionStartIncluding":"17.7","versionEndIncluding":"17.12"} |
| oracle | primavera_unifier | 16.1 |
| oracle | primavera_unifier | 16.2 |
| oracle | primavera_unifier | 18.8 |
| oracle | primavera_unifier | 19.12 |
| oracle | retail_merchandising_system | 15.0.3 |
| oracle | retail_merchandising_system | 16.0.2 |
| oracle | retail_merchandising_system | 16.0.3 |
| oracle | retail_sales_audit | 14.1 |
| oracle | siebel_engineering_-_installer_&_deployment | * {"versionEndIncluding":"2.20.5"} |
| oracle | siebel_ui_framework | * {"versionEndIncluding":"20.5"} |
| oracle | siebel_ui_framework | 20.6 |
| oracle | webcenter_portal | 12.2.1.3.0 |
| oracle | webcenter_portal | 12.2.1.4.0 |
| oracle | webcenter_sites | 12.2.1.3.0 |
| oracle | webcenter_sites | 12.2.1.4.0 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- github.com — Patch, Third Party Advisory
- issues.apache.org — Issue Tracking, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org
- lists.fedoraproject.org
- medium.com
- seclists.org — Issue Tracking, Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- github.com — Patch, Third Party Advisory
- issues.apache.org — Issue Tracking, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org
- lists.fedoraproject.org
- medium.com
- seclists.org — Issue Tracking, Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
PUBLISHED 2019-10-01T13:15:10-04:00
MODIFIED 2026-10-08T17:17:16-04:00
INGESTED 2026-10-10T20:50:18-04:00