Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-19360

35
FAUCET Score

CVE-2018-19360 is a critical deserialization vulnerability affecting FasterXML jackson-databind versions 2.x before 2.9.8, as well as products from Debian, Oracle, and Red Hat. This flaw allows attackers to achieve unspecified impact by exploiting the failure to block the axis2-transport-jms class during polymorphic deserialization. With a CVSS score of 9.8, it presents a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its high severity warrants immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.0, <= 2.6.7.2CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.7.0, < 2.7.9.5CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.8.0, < 2.8.11.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.8CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
10.60%
Probability of exploitation in next 30 days
EPSS Percentile
95.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1060 is in the 91st percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.7.9.5
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.9.8
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.8.11.3
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R13Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 6.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 6.4.12Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 7.4Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Virtualization 6.4.8Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Continuous DeliveryFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5:v3.11.153-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-logging-elasticsearch6:v4.6.0-202104161407.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-maven35-jackson-databind-0:2.7.6-2.5.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only RHOAR
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.1Fixed in: openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Logging 5.0Fixed in: openshift-logging/elasticsearch6-rhel8:v5.0.3-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Data GridFixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 6.3Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.5.0Fixed in: jackson-databind
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss A-MQ 6Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat JBoss Fuse Integration Service 2Fixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: jackson-databind
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: openshift-elasticsearch-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: elasticsearch-cloud-kubernetes
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: openshift-elasticsearch-plugin

Vendor Advisories (2)

mavenGHSA-f9hv-mg5h-xcw9critical

Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization

Jan 4, 2019
redhatCVE-2018-19360Important

jackson-databind: improper polymorphic deserialization in axis2-transport-jms class

Nov 18, 2018

References

access.redhat.com / errata/RHBA-2019:0959
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0877
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1782
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1797
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1822
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1823
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2804
access.redhat.com / errata/RHSA-2019:2858
access.redhat.com / errata/RHSA-2019:3002
access.redhat.com / errata/RHSA-2019:3140
access.redhat.com / errata/RHSA-2019:3149
access.redhat.com / errata/RHSA-2019:3892
access.redhat.com / errata/RHSA-2019:4037
github.com / FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
PatchThird Party Advisory
github.com / FasterXML/jackson-databind/issues/2186
Issue TrackingPatchThird Party Advisory
github.com / FasterXML/jackson/wiki/Jackson-Release-2.9.8
PatchRelease NotesThird Party Advisory
issues.apache.org / jira/browse/TINKERPOP-2121
Issue TrackingThird Party Advisory
lists.apache.org / thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3%40%3Cdevnull.infra.apache.org%3E
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
lists.apache.org / thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
lists.apache.org / thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
lists.apache.org / thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
lists.apache.org / thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
lists.debian.org / debian-lts-announce/2019/03/msg00005.html
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/May/68
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190530-0003
Third Party Advisory
debian.org / security/2019/dsa-4452
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
securityfocus.com / bid/107985
Third Party AdvisoryVDB Entry