Security readout for executives and security teams
Plain-English summary
This issue affects older jackson-databind 2.x versions when risky polymorphic typing is enabled on an internet-facing JSON endpoint and logback is present. The bundle does not provide a CVSS score, but matching services should be treated as meaningful application risk because attacker-controlled JSON reaches deserialization logic.
Executive priority
Prioritize systems that expose JSON APIs to the internet and run older jackson-databind. Internal-only systems without Default Typing or logback appear lower priority based on the provided evidence.
Technical view
CVE-2019-14439 is a jackson-databind polymorphic typing issue before 2.9.9.2. Exposure depends on Default Typing, external JSON input, and logback in the classpath. Apache TomEE references updated jackson-databind to 2.9.9.3 to mitigate this CVE alongside related jackson-databind CVEs.
Likely exposure
Most exposed assets are Java services using jackson-databind 2.x before 2.9.9.2 with Default Typing enabled for externally reachable JSON parsing and logback available at runtime.
Exploitation context
The provided sources do not show active exploitation, and KEV is false. Risk is conditional: an attacker would need a reachable JSON endpoint processed by vulnerable jackson-databind configuration with the relevant classpath condition.
Researcher notes
The record lacks CVSS, CWE, and detailed exploit mechanics. Treat the CVE as configuration-dependent. Avoid assuming all jackson-databind users are vulnerable; validate version, Default Typing, external input path, and logback presence.
Mitigation direction
- Upgrade jackson-databind to at least 2.9.9.2, or vendor-recommended fixed versions.
- Review Apache TomEE guidance referencing jackson-databind 2.9.9.3 mitigation.
- Disable unnecessary Default Typing on externally exposed JSON inputs.
- Check Debian, Fedora, Red Hat, and application vendor advisories for packaged fixes.
Validation and detection
- Inventory Java applications using jackson-databind 2.x before 2.9.9.2.
- Confirm whether Default Typing is enabled globally or per property.
- Identify externally exposed JSON endpoints using jackson-databind deserialization.
- Check runtime classpaths for logback jars.
- Verify patched package versions after dependency or vendor updates.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-14439 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- [debian-lts-announce] 20190812 [SECURITY] [DLA 1879-1] jackson-databind security updateCVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439CVE reference · mailing-list, x_refsource_MLIST
- [cassandra-commits] 20190919 [jira] [Created] (CASSANDRA-15328) Bump jackson version to >= 2.9.9.3 to address security vulnerabilitiesCVE reference · mailing-list, x_refsource_MLIST
- FEDORA-2019-ae6a703b8fCVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2019-fb23eccc03CVE reference · vendor-advisory, x_refsource_FEDORA
- DSA-4542CVE reference · vendor-advisory, x_refsource_DEBIAN
- 20191007 [SECURITY] [DSA 4542-1] jackson-databind security updateCVE reference · mailing-list, x_refsource_BUGTRAQ
- [drill-dev] 20191017 Dependencies used by Drill contain known vulnerabilitiesCVE reference · mailing-list, x_refsource_MLIST
- [drill-dev] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilitiesCVE reference · mailing-list, x_refsource_MLIST
- [drill-issues] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilitiesCVE reference · mailing-list, x_refsource_MLIST
- RHSA-2019:3200CVE reference · vendor-advisory, x_refsource_REDHAT
- [nifi-commits] 20191113 svn commit: r1869773 - /nifi/site/trunk/security.htmlCVE reference · mailing-list, x_refsource_MLIST
- [nifi-commits] 20200123 svn commit: r1873083 - /nifi/site/trunk/security.htmlCVE reference · mailing-list, x_refsource_MLIST
- https://www.oracle.com/security-alerts/cpuapr2020.htmlCVE reference · x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujul2020.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
