CVE-2017-7525 affects Jackson Databind when applications pass attacker-controlled JSON to ObjectMapper.readValue while global polymorphic typing has been enabled with ObjectMapper.enableDefaultTyping(). Attackers can abuse unsafe gadget types, including com.sun.rowset.JdbcRowSetImpl in susceptible dependency environments, to achieve unauthenticated code execution. Jackson also addressed the related CVE-2017-15095 by expanding restrictions on dangerous JDK types used in polymorphic deserialization; affected fixes targeted versions 2.8.10 and 2.9.1, with a 2.7 backport.
Red Hat released updates for numerous products, including JBoss EAP, OpenShift Container Platform, JBoss Data Grid, Fuse, and Software Collections; RHSA-2017:1839 supplied rh-eclipse46-jackson-databind-2.6.3-2.3.el7 for affected RHEL 7 deployments. Debian later shipped LTS updates for Jessie and Stretch that fixed CVE-2017-7525, CVE-2017-15095, and the Jackson XML XXE flaw CVE-2019-10172. Organizations should update affected Jackson packages and avoid globally enabling default typing, using explicit @JsonTypeInfo only where type metadata is required. Apache Solr's review found its 7.7 branch did not enable default typing and constrained @JsonTypeInfo to named subtypes, reducing exposure to these exploit paths.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
An Apache Solr source review concluded that older Jackson polymorphic-deserialization RCE issues did not appear exploitable in Solr 7.7 because default typing was not enabled and @JsonTypeInfo was restricted to named subtypes. Solr maintainers said no 7.x backport of the Hadoop 3.x upgrade associated with SOLR-13110 was planned.
FasterXML accepted a 2.7-branch backport of the CVE-2017-15095 blacklist changes through commit e865a7a.
FasterXML opened and completed issue #1737 for CVE-2017-15095, expanding jackson-databind's blocked JDK types for polymorphic deserialization. The initial fix, commit ddfddfb, targeted versions 2.8.10 and 2.9.1.
A user opened FasterXML jackson-databind issue #1723, reporting that CVE-2017-7525 affected version 2.8.9 and pre-release builds of 2.9.0. The report described an RCE-related deserialization path involving com.sun.rowset.JdbcRowSetImpl.
Red Hat issued security advisories including RHSA-2017:1839 to fix CVE-2017-7525 in jackson-databind. The flaw could allow unauthenticated code execution when malicious input was processed by ObjectMapper.readValue with global default typing enabled.
A FasterXML user opened jackson-databind issue #1599 reporting that default typing could permit arbitrary code or command execution through malicious serialized input. Maintainers began investigating and developing a patch.
An exploitation-focused write-up for the Jackson Databind RCE vulnerability CVE-2017-7525 was published. The supplied reference does not provide technical details of the exploit or explicitly date the underlying disclosure event.
FasterXML locked jackson-databind issue #1737 and limited further discussion to collaborators, directing users to CVE records for fixed-version information.
Debian published DLA-2342-1 for Debian 9 Stretch and provided libjackson-json-java version 1.9.2-8+deb9u1. The advisory addressed CVE-2017-7525, CVE-2017-15095, and CVE-2019-10172.
Debian published DLA 2091-1 for Debian 8 Jessie, updating libjackson-json-java to version 1.9.2-3+deb8u1. The update addressed CVE-2017-7525, CVE-2017-15095, and CVE-2019-10172.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcelists.debian.org
Open sourcelists.debian.org
Open sourcelists.apache.org
Open sourcegithub.com
Open sourceadamcaudill.com
Open sourcegithub.com
Open sourcebugzilla.redhat.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.