Security readout for executives and security teams
Plain-English summary
This is a remote code execution risk in older FasterXML jackson-databind when default typing is used with Ehcache present. Affected applications may let crafted data influence object creation. The bundle shows multiple downstream projects and Linux distributions shipping updates, but no KEV listing or cited active exploitation.
Executive priority
Prioritize remediation where vulnerable Jackson is reachable in production Java services. RCE impact justifies urgency, but the evidence provided does not prove active exploitation or broad unauthenticated reachability in every deployment.
Technical view
SubTypeValidator.java in jackson-databind before 2.9.9.2 mishandles default typing with net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup. The reported impact is remote code execution. Exposure depends on vulnerable jackson-databind, Ehcache availability, and application use of default typing on attacker-influenced data.
Likely exposure
Most likely in Java applications or packaged products that embed jackson-databind before 2.9.9.2 and include Ehcache. The source bundle lists no CPEs, so dependency inventory is required rather than product-name matching.
Exploitation context
The supplied sources support remote code execution potential, but do not show active exploitation. KEV is false in the bundle. Treat internet-facing JSON-processing services as higher priority when default typing and vulnerable dependencies are present.
Researcher notes
The record has limited structured metadata: no CVSS, CWE, CPEs, or complete product list. Validate exposure by dependency graph, runtime classpath, and Jackson configuration. Downstream references show dependency upgrades in Debian and Apache projects.
Mitigation direction
- Upgrade jackson-databind to 2.9.9.2 or later.
- Apply vendor package updates from Debian, Red Hat, Fedora, or affected upstream projects.
- Check whether bundled applications ship vulnerable jackson-databind transitively.
- Review vendor guidance before changing serialization settings in production.
- Prioritize externally reachable Java services processing JSON data.
Validation and detection
- Generate a dependency inventory for jackson-databind versions.
- Check runtime classpaths for Ehcache presence.
- Review code or configuration for Jackson default typing usage.
- Confirm vendor advisories are applied for packaged products.
- Retest application serialization paths after dependency upgrades.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-14379 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- [debian-lts-announce] 20190812 [SECURITY] [DLA 1879-1] jackson-databind security updateCVE reference · mailing-list, x_refsource_MLIST
- [ambari-commits] 20190813 [ambari] branch branch-2.7 updated: AMBARI-25352 : Upgrade fasterxml jackson dependency due to CVE-2019-14379 (#3066)CVE reference · mailing-list, x_refsource_MLIST
- [ambari-commits] 20190813 [ambari] branch trunk updated: AMBARI-25352 : Upgrade fasterxml jackson dependency due to CVE-2019-14379(trunk) (#3067)CVE reference · mailing-list, x_refsource_MLIST
- [pulsar-commits] 20190822 [GitHub] [pulsar] massakam opened a new pull request #5011: [security] Upgrade jackson-databindCVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- RHSA-2019:2743CVE reference · vendor-advisory, x_refsource_REDHAT
- FEDORA-2019-99ff6aa32cCVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2019-ae6a703b8fCVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2019-fb23eccc03CVE reference · vendor-advisory, x_refsource_FEDORA
- [tinkerpop-commits] 20190924 [GitHub] [tinkerpop] justinchuch opened a new pull request #1200: Upgrade jackson due to CVE issuesCVE reference · mailing-list, x_refsource_MLIST
- RHSA-2019:2858CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:2937CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:2935CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:2936CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:2938CVE reference · vendor-advisory, x_refsource_REDHAT
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
