Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4589)
WordPress Plugin WordPress Social Sharing-Social Warfare Cross-Site Scripting (3.5.3)
GlassFish CVE-2012-0551 Vulnerability (CVE-2012-0551)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2348)