{
  "threat_severity" : "Moderate",
  "public_date" : "2019-09-17T00:00:00Z",
  "bugzilla" : {
    "description" : "jackson-databind: Serialization gadgets in classes of the ehcache package",
    "id" : "1758167",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1758167"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-502",
  "details" : [ "A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.", "A flaw was discovered in FasterXML jackson-databind, where it would permit polymorphic deserialization of malicious objects using the ehcache gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code." ],
  "statement" : "Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.\nRed Hat OpenShift Container Platform does ship the vulnerable component, but does not enable the unsafe conditions needed to exploit, lowering their vulnerability impact.",
  "affected_release" : [ {
    "product_name" : "EAP-CD 19 Tech Preview",
    "release_date" : "2020-05-28T00:00:00Z",
    "advisory" : "RHSA-2020:2333",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_cd:19",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat AMQ Streams 1",
    "release_date" : "2019-10-24T00:00:00Z",
    "advisory" : "RHSA-2019:3200",
    "cpe" : "cpe:/a:redhat:amq_streams:1",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat Data Grid 7.3.6",
    "release_date" : "2020-05-26T00:00:00Z",
    "advisory" : "RHSA-2020:2321",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7.3",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat Decision Manager 7",
    "release_date" : "2020-03-18T00:00:00Z",
    "advisory" : "RHSA-2020:0899",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7.7",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat Fuse 7.7.0",
    "release_date" : "2020-07-28T00:00:00Z",
    "advisory" : "RHSA-2020:3192",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat JBoss EAP 7.2",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0164",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-apache-cxf-0:3.2.11-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-glassfish-jsf-0:2.3.5-6.SP3_redhat_00004.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hal-console-0:3.0.19-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hibernate-0:5.3.14-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hibernate-validator-0:6.0.18-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-annotations-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-core-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-databind-0:2.9.10.1-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-dataformats-binary-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-dataformats-text-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-jaxrs-providers-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-modules-base-0:2.9.10-2.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-modules-java8-0:2.9.10-1.redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jberet-0:1.3.5-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-ejb-client-0:4.0.27-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-3.SP2_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-server-migration-0:1.3.1-7.Final_redhat_00007.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-3.SP2_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-netty-0:4.1.42-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-picketlink-bindings-0:2.5.5-21.SP12_redhat_00010.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-undertow-0:2.0.28-2.SP1_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-undertow-jastow-0:2.0.8-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-weld-core-0:3.0.6-3.Final_redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-0:7.2.6-5.GA_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-http-client-0:1.0.18-2.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0159",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-transaction-client-0:1.1.8-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-apache-cxf-0:3.2.11-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-glassfish-jsf-0:2.3.5-6.SP3_redhat_00004.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hal-console-0:3.0.19-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hibernate-0:5.3.14-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hibernate-validator-0:6.0.18-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-annotations-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-core-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-databind-0:2.9.10.1-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-dataformats-binary-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-dataformats-text-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-jaxrs-providers-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-modules-base-0:2.9.10-2.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-modules-java8-0:2.9.10-1.redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jberet-0:1.3.5-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-ejb-client-0:4.0.27-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-3.SP2_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-server-migration-0:1.3.1-7.Final_redhat_00007.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-3.SP2_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-netty-0:4.1.42-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-picketlink-bindings-0:2.5.5-21.SP12_redhat_00010.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-undertow-0:2.0.28-2.SP1_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-undertow-jastow-0:2.0.8-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-weld-core-0:3.0.6-3.Final_redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-0:7.2.6-5.GA_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-http-client-0:1.0.18-2.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0160",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-transaction-client-0:1.1.8-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-apache-cxf-0:3.2.11-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-glassfish-jsf-0:2.3.5-6.SP3_redhat_00004.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hal-console-0:3.0.19-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hibernate-0:5.3.14-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hibernate-validator-0:6.0.18-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-annotations-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-core-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-databind-0:2.9.10.1-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-dataformats-binary-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-dataformats-text-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-jaxrs-providers-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-modules-base-0:2.9.10-2.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-modules-java8-0:2.9.10-1.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jberet-0:1.3.5-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-ejb-client-0:4.0.27-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-3.SP2_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-server-migration-0:1.3.1-7.Final_redhat_00007.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-3.SP2_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-netty-0:4.1.42-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-picketlink-bindings-0:2.5.5-21.SP12_redhat_00010.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-undertow-0:2.0.28-2.SP1_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-undertow-jastow-0:2.0.8-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-weld-core-0:3.0.6-3.Final_redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-0:7.2.6-5.GA_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-http-client-0:1.0.18-2.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0161",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-transaction-client-0:1.1.8-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat Openshift Application Runtimes Vert.x 3.8.3",
    "release_date" : "2019-11-18T00:00:00Z",
    "advisory" : "RHSA-2019:3901",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "release_date" : "2020-03-18T00:00:00Z",
    "advisory" : "RHSA-2020:0895",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7.7",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.3",
    "release_date" : "2020-02-06T00:00:00Z",
    "advisory" : "RHSA-2020:0445",
    "cpe" : "cpe:/a:redhat:jboss_single_sign_on:7.3",
    "package" : "jackson-databind"
  }, {
    "product_name" : "Text-Only RHOAR",
    "release_date" : "2020-05-18T00:00:00Z",
    "advisory" : "RHSA-2020:2067",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat BPM Suite 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "pki-deps:10.6/jackson-databind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat JBoss A-MQ 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:jboss_amq:6"
  }, {
    "product_name" : "Red Hat JBoss Data Virtualization 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:jboss_data_virtualization:6"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4",
    "fix_state" : "Out of support scope",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4"
  }, {
    "product_name" : "Red Hat OpenShift Application Runtimes",
    "fix_state" : "Affected",
    "package_name" : "jackson-databind",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.10",
    "fix_state" : "Will not fix",
    "package_name" : "elasticsearch-cloud-kubernetes",
    "cpe" : "cpe:/a:redhat:openshift:3.10"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.10",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-elasticsearch-plugin",
    "cpe" : "cpe:/a:redhat:openshift:3.10"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Will not fix",
    "package_name" : "openshift3/ose-logging-elasticsearch5",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.9",
    "fix_state" : "Will not fix",
    "package_name" : "elasticsearch-cloud-kubernetes",
    "cpe" : "cpe:/a:redhat:openshift:3.9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.9",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-elasticsearch-plugin",
    "cpe" : "cpe:/a:redhat:openshift:3.9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-logging-elasticsearch5",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Out of support scope",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:10",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Will not fix",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:13",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenStack Platform 14 (Rocky)",
    "fix_state" : "Will not fix",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:14",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Not affected",
    "package_name" : "candlepin",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-maven35-jackson-databind",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-17267\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-17267" ],
  "name" : "CVE-2019-17267",
  "mitigation" : {
    "value" : "The following conditions are needed for an exploit, we recommend avoiding all if possible\n* Deserialization from sources you do not control\n* `enableDefaultTyping()`\n* `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`",
    "lang" : "en:us"
  },
  "csaw" : false
}