Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-35728 Details
Description
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 27, 2025Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| fasterxml jackson-databind | >= 2.0.0, < 2.6.7.5 >= 2.7.0, < 2.9.10.8 |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| netapp service level manager | All versions |
CPE
Remediation
| |
| oracle agile product lifecycle management | 9.3.6 |
CPE
Remediation
| |
| oracle application testing suite | 13.3.0.1 |
CPE
Remediation
| |
| oracle autovue | 21.0.2 |
CPE
Remediation
| |
| oracle banking corporate lending process management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking credit facilities process management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking extensibility workbench | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking supply chain finance | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking treasury management | 14.4 |
CPE
Remediation
| |
| oracle banking virtual account management | 14.2.0 14.3.0 14.5.0 |
CPE
Remediation
| |
| oracle blockchain platform | <= 21.1.2 |
CPE
Remediation
| |
| oracle commerce platform | >= 11.3.0, <= 11.3.2 11.2.0 |
CPE
Remediation
| |
| oracle communications billing and revenue management | 7.5.0.23.0 12.0.0.3.0 |
CPE
Remediation
| |
| oracle communications cloud native core policy | 1.14.0 |
CPE
Remediation
| |
| oracle communications cloud native core unified data repository | 1.4.0 |
CPE
Remediation
| |
| oracle communications convergent charging controller | 12.0.4.0.0 |
CPE
Remediation
| |
| oracle communications diameter signaling route | >= 8.0.0.0, <= 8.5.0.0 |
CPE
Remediation
| |
| oracle communications element manager | >= 8.2.0.0, <= 8.2.4.0 |
CPE
Remediation
| |
| oracle communications evolved communications application server | 7.1 |
CPE
Remediation
| |
| oracle communications network charging and control | 12.0.4.0.0 |
CPE
Remediation
| |
| oracle communications policy management | 12.5.0 |
CPE
Remediation
| |
| oracle communications services gatekeeper | 7.0 |
CPE
Remediation
| |
| oracle communications session report manager | >= 8.0.0.0, <= 8.2.2.1 |
CPE
Remediation
| |
| oracle communications session route manager | >= 8.2.0.0, <= 8.2.2.1 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.4.1 |
CPE
Remediation
| |
| oracle data integrator | 12.2.1.4.0 |
CPE
Remediation
| |
| oracle goldengate application adapters | 19.1.0.0.0 |
CPE
Remediation
| |
| oracle insurance policy administration | >= 11.1.0, <= 11.3.0 11.0.2 |
CPE
Remediation
| |
| oracle insurance rules palette | >= 11.1.0, <= 11.3.0 11.0.2 |
CPE
Remediation
| |
| oracle jd edwards enterpriseone orchestrator | < 9.2.5.3 |
CPE
Remediation
| |
| oracle jd edwards enterpriseone tools | < 9.2.5.3 |
CPE
Remediation
| |
| oracle primavera gateway | >= 17.12.0, <= 17.12.11 >= 18.8.0, <= 18.8.11 >= 19.12.0, <= 19.12.10 20.12.0 |
CPE
Remediation
| |
| oracle primavera unifier | >= 17.7, <= 17.12 >= 18.8, <= 19.12 20.12 |
CPE
Remediation
| |
| oracle retail customer management and segmentation foundation | >= 16.0, <= 19.0 |
CPE
Remediation
| |
| oracle retail merchandising system | 15.0.3 |
CPE
Remediation
| |
| oracle retail service backbone | 14.1.3.2 15.0.3.1 16.0.3.0 |
CPE
Remediation
| |
| oracle retail xstore point of service | 16.0.6 17.0.4 18.0.3 19.0.2 |
CPE
Remediation
| |
| oracle webcenter portal | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Modified Analysis | [email protected] |
| Aug 27, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 2, 2022 | Modified Analysis | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| Apr 28, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 3, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Nov 17, 2021 | Modified Analysis | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Apr 30, 2021 | Modified Analysis | [email protected] |
| Apr 24, 2021 | CVE Modified | [email protected] |
| Feb 1, 2021 | Modified Analysis | [email protected] |
| Jan 29, 2021 | CVE Modified | [email protected] |
| Jan 21, 2021 | Reanalysis | [email protected] |
| Dec 30, 2020 | Initial Analysis | [email protected] |