Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Checkout Manager Multiple Unspecified Vulnerabilities (3.6.9)
Drupal Core 8.7.0 Directory Traversal (8.7.0)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5323)
WordPress Plugin Extensive VC Addons for WPBakery page builder Local File Inclusion (1.9)