CVE-2019-10219
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Affected (422)
Products: Redhat: Hibernate Validator, Fuse, Jboss Data Grid, Jboss Enterprise Application Platform, Openshift Application Runtimes, Single Sign On · Netapp: Active Iq Unified Manager, Element, Management Services For Element Software And Netapp Hci, Snapcenter Plug In · Oracle: Access Manager, Agile Engineering Data Management, Agile Plm, Agile Product Lifecycle Analytics, Agile Product Lifecycle Management Integration Pack, Airlines Data Model, Application Express, Application Performance Management, Application Testing Suite, Argus Analytics, Argus Insight, Argus Safety, Banking Apis, Banking Deposits And Lines Of Credit Servicing, Banking Digital Experience, Banking Enterprise Default Management, Banking Enterprise Default Managment, Banking Loans Servicing, Banking Party Management, Banking Platform, Bi Publisher, Big Data Spatial And Graph, Business Activity Monitoring, Business Intelligence, Business Process Management Suite, Clinical, Commerce Guided Search, Commerce Platform, Communications Application Session Controller, Communications Billing And Revenue Management, Communications Billing And Revenue Management Elastic Charging Engine, Communications Calendar Server, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Console, Communications Cloud Native Core Network Function Cloud Native Environment, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Service Communication Proxy, Communications Cloud Native Core Unified Data Repository, Communications Contacts Server, Communications Converged Application Server Service Controller, Communications Convergence, Communications Convergent Charging Controller, Communications Data Model, Communications Design Studio, Communications Diameter Signaling Route, Communications Eagle Application Processor, Communications Instant Messaging Server, Communications Interactive Session Recorder, Communications Messaging Server, Communications Metasolv Solution, Communications Network Charging And Control, Communications Network Integrity, Communications Offline Mediation Controller, Communications Operations Monitor, Communications Pricing Design Center, Communications Service Broker, Communications Services Gatekeeper, Communications Session Border Controller, Communications Unified Inventory Management, Communications Webrtc Session Controller, Data Integrator, Database Server, Demantra Demand Management, Documaker, E Business Suite, Enterprise Communications Broker, Enterprise Data Quality, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Enterprise Session Border Controller, Essbase, Essbase Administration Services, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Enterprise Case Management, Financial Services Foreign Account Tax Compliance Act Management, Financial Services Model Management And Governance, Financial Services Trade Based Anti Money Laundering, Flexcube Investor Servicing, Flexcube Private Banking, Fusion Middleware, Fusion Middleware Mapviewer, Goldengate, Goldengate Application Adapters, Graalvm, Graph Server And Client, Health Sciences Clinical Development Analytics, Health Sciences Inform Crf Submit, Health Sciences Information Manager, Healthcare Data Repository, Healthcare Foundation, Healthcare Translational Research, Hospitality Cruise Shipboard Property Management System, Hospitality Opera 5 Property Services, Hospitality Reporting And Analytics, Hospitality Suite8, Http Server, Hyperion Financial Management, Hyperion Ilearning, Hyperion Infrastructure Technology, Instantis Enterprisetrack, Insurance Data Gateway, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration, Insurance Policy Administration J2ee, Insurance Rules Palette, Java Se, Jd Edwards Enterpriseone Orchestrator, Jdk, Managed File Transfer, Mysql Cluster, Mysql Connectors, Mysql Server, Mysql Workbench, Nosql Database, Oss Support Tools, Peoplesoft Enterprise Cs Sa Integration Pack, Peoplesoft Enterprise People Tools, Peoplesoft Enterprise Peopletools, Policy Automation, Primavera Analytics, Primavera Data Warehouse, Primavera Gateway, Primavera P6 Enterprise Project Portfolio Management, Primavera P6 Professional Project Management, Primavera Portfolio Management, Primavera Unifier, Rapid Planning, Real Time Decision Server, Real User Experience Insight, Rest Data Services, Retail Allocation, Retail Analytics, Retail Assortment Planning, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Customer Management And Segmentation Foundation, Retail Eftlink, Retail Extract Transform And Load, Retail Financial Integration, Retail Fiscal Management, Retail Integration Bus, Retail Invoice Matching, Retail Merchandising System, Retail Order Broker, Retail Order Management System, Retail Point Of Sale, Retail Predictive Application Server, Retail Price Management, Retail Returns Management, Retail Service Backbone, Retail Size Profile Optimization, Retail Xstore Point Of Service, Sd Wan Aware, Sd Wan Edge, Secure Backup, Siebel Applications, Solaris, Spatial Studio, Thesaurus Management System, Timesten In Memory Database, Utilities Framework, Utilities Testing Accelerator, Vm Virtualbox, Webcenter Portal, Weblogic Server, Zfs Storage Appliance Kit, Zfs Storage Application Integration Engineering Software, Fujitsu M10 1 Firmware, Fujitsu M10 4 Firmware, Fujitsu M10 4s Firmware, Fujitsu M12 1 Firmware, Fujitsu M12 2 Firmware, Fujitsu M12 2s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.18 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.3.0 | |
| Version 6.2.1.0 | |
| Version 9.3.3 | |
| Version 3.6.1 | |
| Version 3.6 | |
| Version 12.1.1.0.0 | |
| Version 21.1.4 | |
| Version 13.4.1.0 | |
| Version 13.3.0.1 | |
| Version 8.2.1 | |
| Version 8.2.1 | |
| Version 8.2.1 | |
| Version 18.1 | |
| Version 2.12.0 | |
| Version 17.2 | |
| Version 2.10.0 | |
| From 2.3.0 to 2.4.0 | |
| Version 2.12.0 | |
| Version 2.7.0 | |
| From 2.3.0 to 2.4.1 | |
| Version 11.1.1.9.0 | |
| Version 23.1 | |
| Version 12.2.1.4.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 | |
| Version 5.2.1 | |
| Version 11.3.2 | |
| From 11.3.0 to 11.3.2 | |
| Version 3.9.0 | |
| Version 12.0.0.3 | |
| Version 11.3 | |
| Version 8.0.0.5.0 | |
| Version 1.8.0 | |
| Version 1.10.0 | |
| Version 1.7.0 | |
| Version 1.9.0 | |
| Version 1.14.0 | |
| Version 1.14.0 | |
| Version 1.15.0 | |
| Version 1.14.0 | |
| Version 1.14.0 | |
| Version 8.0.0.3.0 | |
| Version 6.2 | |
| Version 3.0.2.2.0 | |
| From 12.0.1.0.0 to 12.0.4.0.0 | |
| Version 11.3.2.1.0 | |
| Version 7.3.4 | |
| From 8.0.0.0 to 8.5.1.0 | |
| From 16.1 to 16.4 | |
| Version 10.0.1.5.0 | |
| Version 6.3 | |
| Version 8.1 | |
| Version 6.3.1 | |
| From 12.0.1.0.0 to 12.0.4.0.0 | |
| Version 7.3.5 | |
| Version 12.0.0.3 | |
| Version 3.4 | |
| Version 12.0.0.3.0 | |
| Version 6.2 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 7.3.0 | |
| Version 7.2.0 | |
| Version 12.2.1.3.0 | |
| Version 12.1.0.1 | |
| From 12.2.6 to 12.2.11 | |
| From 12.6.0 to 12.6.4 | |
| From 12.2.3 to 12.2.11 | |
| Version 3.3 | |
| Version 12.2.1.3.0 | |
| Version 13.4.0.0 | |
| Version 12.4.0.0 | |
| Version 8.4 | |
| Before 11.1.2.4.47 | |
| Before 11.1.2.4.47 | |
| From 8.0.7 to 8.1.1 | |
| Version 8.0.11 | |
| Version 8.0.11 | |
| Version 8.0.11 | |
| From 8.0.8 to 8.1.1 | |
| Version 8.0.7 | |
| Version 12.0.4 | |
| Version 12.0.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.4.0 | |
| Before 12.3.0.1 | |
| Version 19.1.0.0.0 | |
| Version 20.3.4 | |
| Before 21.4 | |
| Version 4.0.1 | |
| Version 6.2.1 | |
| Version 3.0.2 | |
| Version 7.0.2 | |
| From 7.3.0.0 to 7.3.0.2 | |
| Version 4.1.0 | |
| Version 20.1.0 | |
| Version 5.6 | |
| Version 9.1.0 | |
| Version 8.10.2 | |
| Version 12.2.1.3.0 | |
| Version 11.1.2.4 | |
| Version 6.2 | |
| Version 11.2.7.0 | |
| Version 17.1 | |
| Version 11.0.2 | |
| From 5.4.0 to 5.6.0 | |
| Version 11.0.2 | |
| From 11.1.0 to 11.3.0 | |
| From 11.1.0 to 11.3.0 | |
| Version 17.1 | |
| Before 9.2.6.1 | |
| Version 11.0.13 | |
| Version 12.2.1.3.0 | |
| Before 7.4.34 | |
| Before 8.0.27 | |
| Before 5.7.36 | |
| Before 8.0.27 | |
| Before 21.1.12 | |
| Before 2.12.42 | |
| Version 9.0 | |
| Version 8.57 | |
| Version 8.57 | |
| From 12.2.0 to 12.2.24 | |
| Version 18.8.3.3 | |
| Version 18.8.3.3 | |
| From 17.12.0 to 17.12.11 | |
| From 17.12.0.0 to 17.12.0.0-17.12.20.0 | |
| From 17.12.0.0 to 17.12.20.0 | |
| From 18.0.0.0 to 18.0.3.0 | |
| From 17.7 to 17.12 | |
| From 12.2.6 to 12.2.11 | |
| Version 3.2.0.0 | |
| Version 13.4.1.0 | |
| Version 21.2.4 | |
| Version 14.1.3.2 | |
| From 16.0.0 to 16.0.2 | |
| Version 16.0.3 | |
| Version 14.1 | |
| Version 14.1 | |
| From 16.0.0 to 16.0.2 | |
| From 16.0 to 19.0 | |
| Version 16.0.3 | |
| Version 13.2.8 | |
| Version 14.1.3.2 | |
| Version 14.2 | |
| From 16.0.1 to 16.0.3 | |
| Version 15.0.3 | |
| Version 19.0.1 | |
| Version 16.0 | |
| Version 19.5 | |
| Version 14.1 | |
| Version 14.1.3.46 | |
| Version 13.2 | |
| Version 14.1 | |
| From 16.0.1 to 16.0.3 | |
| Version 16.0.3 | |
| Version 17.0.4 | |
| Version 8.2 | |
| Version 9.0 | |
| Version 18.1.0.1.0 | |
| Before 21.12 | |
| Version 10 | |
| Version 21.2.1 | |
| Version 5.2.3 | |
| Before 11.2.2.8.27 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 6.0.0.1.1 | |
| Before 6.1.32 | |
| Version 12.2.1.3.0 | |
| Version 12.1.3.0.0 | |
| Version 8.8 | |
| Version 1.3.3 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M10 1 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M10 4 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M10 4s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M12 1 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M12 2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Oracle Fujitsu M12 2s | All versions |
References (36)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.