CVE-2021-20190
jackson-databind, active iq unified manager, oncommand api services
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVSS
- 8.1
- EPSS
- 7.48% 93.9% percentile
- CISA KEV
- Not listed
- Published
- 2021.01.20