External risk intelligence

FasterXML Jackson Databind Polymorphic Typing Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-16942

This vulnerability resides in a widely used data-binding library (Jackson) frequently integrated into internet-facing web applications and API services that process user-supplied JSON. When configured for default typing, these endpoints become reachable entry points for attackers. Given the prevalence of such deployments in modern application stacks, it is common for this surface to be internet-exposed.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in the FasterXML jackson-databind library, which is commonly used in applications that process JSON data. This vulnerability could potentially allow an attacker to execute malicious code if specific conditions are met, including the presence of certain database connection components and an exposed RMI service. The primary concern is to confirm if your environment utilizes this library in a way that could be exposed to such an attack.

  • A library used for handling data could be exploited.
  • This impacts systems processing external JSON.
  • Confirm relevance and confirm if systems are exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted JSON data to a service that uses the Jackson data-binding library with default typing enabled. If the service also has the `commons-dbcp` library in its classpath and an RMI service endpoint is accessible, the attacker can manipulate the data to execute arbitrary code on the server.

  • Network access to a JSON endpoint.
  • Sending malicious JSON data.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When Default Typing is enabled for an externally exposed JSON endpoint and the `commons-dbcp` jar is present in the classpath, an attacker could exploit this vulnerability by finding an RMI service endpoint to access, potentially leading to the execution of malicious code. This occurs due to mishandling within `org.apache.commons.dbcp.datasources.SharedPoolDataSource` and `org.apache.commons.dbcp.datasources.PerUserPoolDataSource`.

  • Service code execution could occur.
  • Malicious RMI service endpoint access.
  • Compromised service integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for managing this risk, given that the vulnerability lies within the widely adopted jackson-databind library, often integrated into externally facing JSON endpoints. The critical first step is to identify all instances of the affected technology, assess their exposure and business criticality, and locate the accountable owner to plan a risk-based remediation.

  • Identify affected systems and owners.
  • Verify Default Typing and RMI exposure.
  • Plan remediation or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the jackson-databind library?

Jackson-databind is a popular Java library used by developers to convert JSON data into Java objects and vice versa. Many enterprise applications, including those from Oracle, NetApp, and Red Hat, rely on it to handle communication and data storage within their software stacks.

What does CVE-2019-16942 mean?

This CVE identifies a deserialization weakness (CWE-502). It occurs when the library is configured with 'Default Typing' enabled, allowing it to trust incoming data too much. An attacker can craft malicious JSON that tricks the application into executing arbitrary code by abusing specific classes found in the Apache Commons DBCP library.

Do I need specific conditions for this to work?

Yes. The vulnerability only triggers if three things happen together: Default Typing must be explicitly enabled in your Jackson configuration, the Apache Commons DBCP (version 1.4) library must be present in the application's classpath, and the application must be able to reach an RMI service endpoint.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because the affected library is frequently embedded in internet-facing web applications. If your service processes JSON from users and meets the specific configuration requirements, it acts as a potential entry point for unauthorized actions.

How should I respond to this threat?

You should prioritize updating your jackson-databind library to a patched version. Check your dependency management files to identify if you are using a vulnerable range and review your application code to ensure 'Default Typing' is not enabled on endpoints that accept external JSON input.

References