In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:8 pki-deps:10.6/jackson-core to version 0:2.10.0-1.module+el8.2.0+5059+3eb3af25 or higher.
This issue was patched in RHSA-2020:1644.
Note: Versions mentioned in the description apply only to the upstream pki-deps:10.6/jackson-core package and not the pki-deps:10.6/jackson-core package as distributed by RHEL.
See How to fix? for RHEL:8 relevant fixed versions and status.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).