Jboss EAP Deserialization of Untrusted Data Vulnerability - CVE-2018-14720 - Vulnerability Database

Jboss EAP Deserialization of Untrusted Data Vulnerability - CVE-2018-14720

Critical
Reference: CVE-2018-14720
Title: Jboss EAP Deserialization of Untrusted Data Vulnerability
Overview:

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.