CVE-2018-7489 | Oracle Communications Instant Messaging Server 10.0.1 jackson-databind incomplete blacklist (Nessus ID 233045 / ID 236791)
A vulnerability, which was classified as very critical, has been found in Oracle Communications Instant Messaging Server 10.0.1. Affected by this issue is some unknown functionality of the component jackson-databind. The manipulation leads to incomplete blacklist.
This vulnerability is handled as CVE-2018-7489. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.