[WID-SEC-2023-1480] FasterXML Jackson: Schwachstelle ermöglicht Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.9 (mittel) Remoteangriff ja Datum 14.06.2023 Stand UPDATE 07.04.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Produktbeschreibung Jackson ist eine quelloffene Bibliothek zur JSON-Verarbeitung in Java. Produkte UPDATE 06.04.2026 Hitachi Ops Center Viewpoint <11.0.8-00 UPDATE 14.05.2025 IBM QRadar SIEM <7.5.0 UP12 UPDATE 17.12.2024 Hitachi Ops Center UPDATE 01.07.2024 Splunk Splunk Enterprise <9.2.1 Splunk Splunk Enterprise <9.1.4 Splunk Splunk Enterprise <9.0.9 UPDATE 11.06.2024 Dell NetWorker UPDATE 09.04.2024 IBM Operational Decision Manager 8.10.x IBM Operational Decision Manager 8.11.x IBM Operational Decision Manager 8.12.x UPDATE 07.02.2024 Red Hat Enterprise Linux UPDATE 18.10.2023 Open Source Vaadin <24.2.0 14.06.2023 FasterXML Jackson <=2.15.2 Angriff Angriff Ein Angreifer kann eine Schwachstelle in FasterXML Jackson ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability in the FasterXML Jackson library for Java allows an attacker to perform a Denial of Service attack, with a CVSS Base Score of 7.5 (High). The affected versions are Jackson core and databind versions up to and including 2.15.2. The article lists numerous affected downstream products, including specific versions of Splunk Enterprise, IBM QRadar, and Red Hat Enterprise Linux, and directs readers to apply the relevant vendor updates.