Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-14719

34
FAUCET Score

CVE-2018-14719 is a critical deserialization vulnerability in FasterXML jackson-databind 2.x before version 2.9.7, allowing remote attackers to execute arbitrary code by exploiting the failure to block specific blaze-ds-opt and blaze-ds-core classes during polymorphic deserialization. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Despite its critical severity and impact on products from vendors like Debian, NetApp, Oracle, and Red Hat, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.6.7.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.7.0, < 2.7.9.5CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.8.0, < 2.8.11.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.7CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
9.68%
Probability of exploitation in next 30 days
EPSS Percentile
95.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0968 is in the 91st percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.7.9.5
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.9.7
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.8.11.3
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R13Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 6.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 6.4.12Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Virtualization 6.4.8Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Continuous DeliveryFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.1Fixed in: openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202104161407.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only RHOAR
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5:v3.11.153-2
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.3-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data GridFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 6.3Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.5.0Fixed in: jackson-databind
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: openshift-elasticsearch-plugin

Vendor Advisories (2)

mavenGHSA-4gq5-ch57-c2mgcritical

Arbitrary Code Execution in jackson-databind

Jan 4, 2019
redhatCVE-2018-14719Important

jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes

Jul 27, 2018

References

access.redhat.com / errata/RHBA-2019:0959
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0877
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1797
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1822
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1823
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2804
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2858
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3002
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3140
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3149
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3892
Third Party Advisory
access.redhat.com / errata/RHSA-2019:4037
Third Party Advisory
github.com / FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
PatchThird Party Advisory
github.com / FasterXML/jackson-databind/issues/2097
PatchThird Party Advisory
github.com / FasterXML/jackson/wiki/Jackson-Release-2.9.7
PatchRelease NotesThird Party Advisory
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
lists.apache.org / thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
lists.debian.org / debian-lts-announce/2019/03/msg00005.html
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/May/68
Issue TrackingMailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190530-0003
Third Party Advisory
debian.org / security/2019/dsa-4452
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujan2019-5072801.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory