Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-14439

29
FAUCET Score

CVE-2019-14439 is a polymorphic typing vulnerability in FasterXML jackson-databind versions prior to 2.9.9.2, affecting products from vendors like Apache, Debian, and Oracle. This flaw arises when default typing is enabled for an exposed JSON endpoint and the logback jar is present in the classpath. With a CVSS score of 7.5 (High), it presents a low-complexity network attack vector that can lead to high confidentiality impact without requiring user interaction or privileges. While the vulnerability has a high FAUCET risk score, there is no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.6.7.3CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.7.0, < 2.7.9.6CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.8.0, < 2.8.11.4CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.9.2CPE matchmatch criteria
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
10.85%
Probability of exploitation in next 30 days
EPSS Percentile
95.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1085 is in the 93rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.7.9.6
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.6.7.3
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.8.11.4
mavenpatch availablevia ghsa
Product: com.fasterxml.jackson.core:jackson-databindFixed in: 2.9.9.2
nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.6.0Fixed in: jackson-databind
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1Fixed in: jackson-databind
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-elasticsearch-plugin
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-logging-elasticsearch5
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: elasticsearch-cloud-kubernetes
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: openshift-elasticsearch-plugin
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-logging-elasticsearch5
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-maven35-jackson-databind
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: elasticsearch-cloud-kubernetes

Vendor Advisories (3)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
mavenGHSA-gwp4-hfv6-p7hwhigh

Deserialization of untrusted data in FasterXML jackson-databind

Aug 1, 2019
redhatCVE-2019-14439Moderate

jackson-databind: Polymorphic typing issue related to logback/JNDI

Jul 30, 2019

References

access.redhat.com / errata/RHSA-2019:3200
Third Party Advisory
github.com / FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b
Patch
github.com / FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2
PatchProduct
github.com / FasterXML/jackson-databind/issues/2389
Issue TrackingThird Party Advisory
lists.apache.org / thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
lists.apache.org / thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
lists.apache.org / thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
lists.debian.org / debian-lts-announce/2019/08/msg00011.html
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544
seclists.org / bugtraq/2019/Oct/6
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190814-0001
Third Party Advisory
debian.org / security/2019/dsa-4542
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2020.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory