Copy link to clipboard
Copied
does anyone have info in how to fix CVE-2019-17267. I can't find any info online and we are running the lastest verion of FrameMaker 17.0.5.725.
Copy link to clipboard
Copied
Hi,
What is CVE-2019-17267?
Can you give some more info?
Best regards, Winfried
Copy link to clipboard
Copied
CVE-2019-17267 is
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
result-0.filename=jackson-databind-2.13.1,result-0.name=C:\Program Files\Adobe\Adobe FrameMaker 2022\CQConnector\jar\jackson-databind-2.13.1.jar,result-1.filename=jackson-databind-2.9.8,result-1.name=C:\Program Files\Adobe\Adobe FrameMaker 2022\fminit\ditafm\DITA-OT\lib\jackson-databind-2.9.8.jar
Copy link to clipboard
Copied
AFAIK FrameMaker doesn't have that vulnerability - where are you seeing it?
Copy link to clipboard
Copied
Copy link to clipboard
Copied
Are you using DITA?
Copy link to clipboard
Copied
Yes. we are using DITA.
Copy link to clipboard
Copied
Ok, then you need to go have a talk with the FM folks - see https://helpx.adobe.com/contact/enterprise-support.other.html#framemaker for your Adobe Support options. I'd recommend using the tcssup@adobe.com e-mail address as it reaches a team dedicated to Technical Communication Suite products including FrameMaker.
Nobody here is going to be able to fix that for you.
Get ready! An upgraded Adobe Community experience is coming in January.
Learn more