CVE-2017-17485
CRITICAL 9.8EPSS 49.7%
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 49.73% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2018-01-10
- Updated
- 2025-08-27
Proof-of-concept exploits (12)
- Al1ex/CVE-2017-174852★ · 2022-11-16
- ShiftLeftSecurity/HelloShiftLeft-Scala1★ · 2025-09-05
- boonyashka/scala0★ · 2025-09-10
- conikeec/helloshiftleftplay0★ · 2020-01-10
- hdgittest/HelloShiftLeft-Scala0★ · 2025-04-24
- hdgittest/HelloshiftLeft_scala0★ · 2025-04-23
- mymortal/expcode0★ · 2019-01-22
- ongamse/Scala0★ · 2025-05-14
- shadowsock5/jackson-databind-POC19★ · 2020-03-27
- tafamace/CVE-2017-174850★ · 2018-11-19
- wahyuhadi/spel.xml0★ · 2023-03-28
- x7iaob/cve-2017-174850★ · 2019-04-21