Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-14718

36
FAUCET Score

CVE-2018-14718 is a critical deserialization vulnerability affecting FasterXML jackson-databind versions 2.x before 2.9.7, which could allow remote attackers to execute arbitrary code by exploiting a failure to block the slf4j-ext class during polymorphic deserialization. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While the vulnerability is severe and affects products from vendors like Debian, NetApp, Oracle, and Red Hat, there is currently no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.6.7.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.7.0, < 2.7.9.5CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.8.0, < 2.8.11.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.7CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
12.68%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1268 is in the 92nd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (35)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.6.7.3
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.8.11.3
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.9.7
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.7.9.5
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 6.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 6.4.12Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Virtualization 6.4.8Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Continuous DeliveryFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.1Fixed in: openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202104161407.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only RHOAR
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5:v3.11.153-2
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.3-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data GridFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 6.3Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.5.0Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R13Fixed in: jackson-databind
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat JBoss Fuse Integration Service 2Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: openshift-elasticsearch-plugin
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: jackson-databind

Vendor Advisories (2)

mavenGHSA-645p-88qh-w398critical

Arbitrary Code Execution in jackson-databind

Jan 4, 2019
redhatCVE-2018-14718Important

jackson-databind: arbitrary code execution in slf4j-ext class

Jul 27, 2018

References

access.redhat.com / errata/RHBA-2019:0959
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0877
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1797
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1822
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1823
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2804
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2858
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3002
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3140
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3149
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3892
Third Party Advisory
access.redhat.com / errata/RHSA-2019:4037
Third Party Advisory
github.com / FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
PatchThird Party Advisory
github.com / FasterXML/jackson-databind/issues/2097
PatchThird Party Advisory
github.com / FasterXML/jackson/wiki/Jackson-Release-2.9.7
PatchRelease NotesThird Party Advisory
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286%40%3Cdev.lucene.apache.org%3E
lists.apache.org / thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f%40%3Cdev.lucene.apache.org%3E
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df%40%3Cdev.lucene.apache.org%3E
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
lists.apache.org / thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache.org%3E
lists.debian.org / debian-lts-announce/2019/03/msg00005.html
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/May/68
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190530-0003
Third Party Advisory
debian.org / security/2019/dsa-4452
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
Third Party Advisory
oracle.com / security-alerts/cpujan2020.html
Third Party Advisory
oracle.com / security-alerts/cpuoct2020.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujan2019-5072801.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory
securityfocus.com / bid/106601
Third Party AdvisoryVDB Entry