S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 10, 2025

CVE-2020-9548 Scanner

CVE-2020-9548 Scanner - Remote Code Execution vulnerability in Jackson Databind

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9548
9.8
CVSS

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

FasterXML's Jackson Databind is a widely used Java library for processing JSON data, commonly employed in various software applications for data binding. Organizations across industries use Jackson Databind for API development and data manipulation tasks. With its rich feature set, it simplifies JSON data handling, making it a preferred choice for developers. The library's ease of use and flexibility contribute to its popularity. It enables seamless integration of JSON data into Java applications, supporting the communication between different services. Given its extensive usage, any security vulnerabilities in Jackson Databind can have widespread implications.

The Remote Code Execution vulnerability identified in Jackson Databind poses a critical security threat. This flaw allows attackers to execute arbitrary code remotely, potentially compromising affected systems. The vulnerability stems from the library's mishandling of serialization gadgets and typing, specifically involving the "br.com.anteros.dbcp.AnterosDBCPConfig" class. If exploited, it could enable unauthorized access or malicious activities on the affected system. The vulnerability, with its high CVSS score, highlights the need for immediate attention and remediation efforts.

Technical details of the vulnerability reveal that it involves a Remote Code Execution flaw within the Jackson Databind library. Attackers can exploit this by sending specially crafted requests, interacting with serialization gadgets to execute arbitrary code. The vulnerable endpoint is identified in the interaction with certain classes during the serialization process. Affected versions mishandle data, leading to the critical security risk. Proper mechanisms are missing to validate or sanitize incoming data, allowing potential exploitation. The flaw's root cause is linked to inadequate processing of specific class configurations.

Exploitation of this vulnerability could result in severe consequences, including unauthorized access to sensitive data, system compromise, and further lateral movement within networks. Attackers could exploit this to deploy malware, conduct espionage, or initiate large-scale attacks. The critical nature of the vulnerability makes it a viable target for cybercriminals seeking valuable data or system control. Organizations utilizing affected versions face increased risk of data breaches and operational disruptions. The impact highlights the necessity for prompt patching and secure deployment practices.

REFERENCES

Solution Advice
  • Update to Jackson Databind version 2.9.10.5 or later, as the vulnerability is addressed in these versions.
  • Review and restrict network exposure for hosts running Jackson Databind to reduce potential attack vectors.
  • Implement strict input validation and limit deserialization capabilities within your applications.
  • Monitor systems for abnormal activities that may be indicative of exploitation attempts.
  • Regularly review and apply security patches to mitigate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-9548 Scanner - Remote Code Execution vulnerability in Jackson Databind | S4E