Unknown
CVE-2020-14061
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-14061
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Products
- active iq unified manager
- agile plm 9.3.6
- autovue for agile product lifecycle management 21.0.2
- banking digital experience 18.1
- banking digital experience 18.2
- banking digital experience 18.3
- banking digital experience 19.1
- banking digital experience 19.2
- banking digital experience 20.1
- communications calendar server 8.0.0.4.0
- communications contacts server 8.0.0.5.0
- communications diameter signaling router
- communications element manager
- communications evolved communications application server 7.1
- communications instant messaging server 10.0.1.4.0
- communications session report manager
- communications session route manager
- debian linux 8.0
- jackson databind
- steelstore cloud integrated storage
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: