CVE-2020-14062 | FasterXML jackson-databind up to 2.9.10.4 Serialized deserialization (WID-SEC-2024-0794)
A vulnerability marked as critical has been reported in FasterXML jackson-databind up to 2.9.10.4. Affected by this issue is some unknown functionality of the component com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool. This manipulation causes deserialization (Serialized).
This vulnerability is registered as CVE-2020-14062. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.