Blackduck scans have indicated a new vulnerability.
Scanned: 10.7.0.361
https://nvd.nist.gov/vuln/detail/CVE-2020-36518
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
(Even though the CVE entry dates back to 2020 the CVE seems to have been updated recently.)
CVSS score: 7.5
Occurrences:
Release : 10.7.0
Component : Introscope
This issue is related to defect DE531305
To be fixed in APM 10.8