Vulnerabilities in Jackson Databind 

Issue date: 29-04-2019
Affects versions: 13.0, 12.6, 11.2


Affected Product Version(s)

This vulnerability affects all versions of both CMS and delivery applications based on Bloomreach Experience Manager prior to 11.2.12, 12.6.2 and 13.0.1.




Several deserialization flaws were discovered in the jackson-databind module of FasterXML Jackson2, which could allow an attacker to have an unspecified impact by leveraging failure to block certain classes from polymorphic deserialization. See: CVE-2018-1000873CVE-2018-19360, CVE-2018-19361 and CVE-2018-19362

This vulnerability is classified with severity critical. Although default usage of this library within the Hippo CMS product is not vulnerable, project specific usages of the Jackson2 library within a Hippo CMS project may be vulnerable. 

The FasterXML Jackson2 and jackson-databind versions in all supported CMS maintenance versions 11.2.12, 12.6.2, and 13.0.1 has been updated to 2.9.8

  • The version used in the 13.0.0 was previously 2.9.7
  • The version used in the 11.2 and 12.2 series was previously 2.8.11 for jackson and for jackson-databind



Every customer is strongly advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.