Vulnerabilities in Jackson Databind 

Issue date: 01-11-2019
Affects versions: 13.3, 13.2, 12.6, 11.2

Issue ID: SECURITY-123

Affected Product Version(s)

This vulnerability affects all versions of both CMS and delivery applications based on Bloomreach Experience Manager prior to, 12.6.6, 13.2.2, and 13.3.0.




A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

This vulnerability is classified with severity high. Although default usage of this library within the Hippo CMS product is not vulnerable, project specific usages of the Jackson2 library within a Hippo CMS project may be vulnerable. 

The FasterXML jackson-databind version in all supported CMS maintenance versions 11.2.16, 12.6.6, 13.2.2, and 13.3.0 has been updated to



Every customer is strongly advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.