<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for jackson-databind</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:0243-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-01-29T08:37:34Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-01-29T08:37:34Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-01-29T08:37:34Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for jackson-databind</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for jackson-databind fixes the following issues:

jackson-databind was updated to 2.10.5.1:
  * #2589: `DOMDeserializer`: setExpandEntityReferences(false) may
    not prevent external entity expansion in all cases
    (CVE-2020-25649, bsc#1177616)
  * #2787 (partial fix): NPE after add mixin for enum
  * #2679: 'ObjectMapper.readValue('123', Void.TYPE)' throws
    'should never occur'
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container suse/manager/5.0/x86_64/server-attestation:latest-2021-243,Container suse/manager/5.0/x86_64/server:latest-2021-243,Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest-2021-243,Container suse/multi-linux-manager/5.1/x86_64/server:latest-2021-243,Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure-2021-243,Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM-2021-243,Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE-2021-243,Image SLES15-SP4-Manager-Server-4-3-2021-243,Image SLES15-SP4-Manager-Server-4-3-Azure-llc-2021-243,Image SLES15-SP4-Manager-Server-4-3-Azure-ltd-2021-243,Image SLES15-SP4-Manager-Server-4-3-BYOS-2021-243,Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure-2021-243,Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2-2021-243,Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE-2021-243,Image SLES15-SP4-Manager-Server-4-3-EC2-llc-2021-243,Image SLES15-SP4-Manager-Server-4-3-EC2-ltd-2021-243,Image server-attestation-image-2021-243,Image server-image-2021-243,SUSE-2021-243,SUSE-SLE-Module-Development-Tools-15-SP2-2021-243</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210243-1/</URL>
      <Description>Link for SUSE-SU-2021:0243-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-January/008253.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:0243-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1177616</URL>
      <Description>SUSE Bug 1177616</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180391</URL>
      <Description>SUSE Bug 1180391</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181118</URL>
      <Description>SUSE Bug 1181118</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25649/</URL>
      <Description>SUSE CVE CVE-2020-25649 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-35728/</URL>
      <Description>SUSE CVE CVE-2020-35728 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20190/</URL>
      <Description>SUSE CVE CVE-2021-20190 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Container suse/manager/5.0/x86_64/server-attestation:latest">
      <Branch Type="Product Name" Name="Container suse/manager/5.0/x86_64/server-attestation:latest">
        <FullProductName ProductID="Container suse/manager/5.0/x86_64/server-attestation:latest">Container suse/manager/5.0/x86_64/server-attestation:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/manager/5.0/x86_64/server:latest">
      <Branch Type="Product Name" Name="Container suse/manager/5.0/x86_64/server:latest">
        <FullProductName ProductID="Container suse/manager/5.0/x86_64/server:latest">Container suse/manager/5.0/x86_64/server:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest">
      <Branch Type="Product Name" Name="Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest">
        <FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest">Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/multi-linux-manager/5.1/x86_64/server:latest">
      <Branch Type="Product Name" Name="Container suse/multi-linux-manager/5.1/x86_64/server:latest">
        <FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server:latest">Container suse/multi-linux-manager/5.1/x86_64/server:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3">Image SLES15-SP4-Manager-Server-4-3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-Azure-llc">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-Azure-llc">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-Azure-llc">Image SLES15-SP4-Manager-Server-4-3-Azure-llc</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-Azure-ltd">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-Azure-ltd">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-Azure-ltd">Image SLES15-SP4-Manager-Server-4-3-Azure-ltd</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS">Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-EC2-llc">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-EC2-llc">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-EC2-llc">Image SLES15-SP4-Manager-Server-4-3-EC2-llc</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-EC2-ltd">
      <Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-EC2-ltd">
        <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-EC2-ltd">Image SLES15-SP4-Manager-Server-4-3-EC2-ltd</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image server-attestation-image">
      <Branch Type="Product Name" Name="Image server-attestation-image">
        <FullProductName ProductID="Image server-attestation-image">Image server-attestation-image</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image server-image">
      <Branch Type="Product Name" Name="Image server-image">
        <FullProductName ProductID="Image server-image">Image server-image</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Development Tools 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Development Tools 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Development Tools 15 SP2" CPE="cpe:/o:suse:sle-module-development-tools:15:sp2">SUSE Linux Enterprise Module for Development Tools 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="jackson-databind-2.10.5.1-3.3.2">
      <FullProductName ProductID="jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="jackson-databind-javadoc-2.10.5.1-3.3.2">
      <FullProductName ProductID="jackson-databind-javadoc-2.10.5.1-3.3.2">jackson-databind-javadoc-2.10.5.1-3.3.2</FullProductName>
    </Branch>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/5.0/x86_64/server-attestation:latest">
      <FullProductName ProductID="Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Container suse/manager/5.0/x86_64/server-attestation:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/5.0/x86_64/server:latest">
      <FullProductName ProductID="Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Container suse/manager/5.0/x86_64/server:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest">
      <FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Container suse/multi-linux-manager/5.1/x86_64/server:latest">
      <FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Container suse/multi-linux-manager/5.1/x86_64/server:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-Azure-llc">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-Azure-llc:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-Azure-llc</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-Azure-ltd">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-Azure-ltd</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-EC2-llc">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-EC2-llc:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-EC2-llc</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-EC2-ltd">
      <FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-EC2-ltd:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image SLES15-SP4-Manager-Server-4-3-EC2-ltd</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image server-attestation-image">
      <FullProductName ProductID="Image server-attestation-image:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image server-attestation-image</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image server-image">
      <FullProductName ProductID="Image server-image:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of Image server-image</FullProductName>
    </Relationship>
    <Relationship ProductReference="jackson-databind-2.10.5.1-3.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Development Tools 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Development Tools 15 SP2:jackson-databind-2.10.5.1-3.3.2">jackson-databind-2.10.5.1-3.3.2 as a component of SUSE Linux Enterprise Module for Development Tools 15 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.</Note>
    </Notes>
    <CVE>CVE-2020-25649</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-attestation-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:jackson-databind-2.10.5.1-3.3.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210243-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25649.html</URL>
        <Description>CVE-2020-25649</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177616</URL>
        <Description>SUSE Bug 1177616</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).</Note>
    </Notes>
    <CVE>CVE-2020-35728</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-attestation-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:jackson-databind-2.10.5.1-3.3.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210243-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-35728.html</URL>
        <Description>CVE-2020-35728</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180391</URL>
        <Description>SUSE Bug 1180391</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20190</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Container suse/multi-linux-manager/5.1/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-Azure-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-BYOS:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-llc:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3-EC2-ltd:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image SLES15-SP4-Manager-Server-4-3:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-attestation-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>Image server-image:jackson-databind-2.10.5.1-3.3.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Development Tools 15 SP2:jackson-databind-2.10.5.1-3.3.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>8.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20210243-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20190.html</URL>
        <Description>CVE-2021-20190</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181118</URL>
        <Description>SUSE Bug 1181118</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
