A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1
Issue date: 15-01-2020Affects versions: 13.4, 13.3, 12.5, 11.2
Issue ID
SECURITY-142
Affected Product Version(s)
13.4.0, 12.6.7 (and previous patch releases)
Severity
Medium
Description
Jackson Databind reported vulnerability CVE-2017-15095 in versions before 2.8.10 and 2.9.1.
The Jackson Databind dependency has been updated to version 2.10.1.
Instructions
Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.