Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)6.3%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2831/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
AnalizadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2731/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2131/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
ModificadaAlta (8.8)8.0%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
ModificadaAlta (8.8)3.1%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
ModificadaCrítica (9.8)19%💥 ExploitFasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+212/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
ModificadaCrítica (9.8)18%💥 ExploitFasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Autovue FOR Agile Product Lifecycle Management+122/3/202017/6/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
AnalizadaCrítica (9.8)4.6%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+272/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
ModificadaCrítica (9.8)8.6%—Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+263/1/202017/6/2026
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaCrítica (9.8)11%💥 PoCConnect2id Nimbus Jose+jwtApache HadoopOracle Communications Cloud Native Core Security Edge Protection ProxyOracle Communications Pricing Design Center+1115/10/201917/6/2026
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
ModificadaCrítica (9.8)5.4%—Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+1812/10/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide…
ModificadaCrítica (9.8)4.9%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+221/10/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint…
ModificadaCrítica (9.8)5.7%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+241/10/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service…
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaAlta (7.5)11%💥 PoCFasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+1430/7/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
ModificadaCrítica (9.8)8.1%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+2029/7/201917/6/2026
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
ModificadaCrítica (9.8)16%💥 PoCSoftwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2726/7/201917/6/2026
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
ModificadaCrítica (9.8)13%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+212/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Orbitaley — Vulnerabilidades