CVE-2019-10219
Last modified
CVE-2019-10219 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Hibernate Validator | < 6.0.18 | — |
| Redhat | Hibernate Validator | 6.1.0 | Alpha1 |
| Redhat | Fuse | 1.0 | — |
| Redhat | Jboss Data Grid | All versions | — |
| Redhat | Jboss Enterprise Application Platform | All versions | — |
| Redhat | Openshift Application Runtimes | All versions | — |
| Redhat | Single Sign-On | All versions | — |
| Redhat | Jboss Enterprise Application Platform | 7.2 | — |
| Redhat | Jboss Enterprise Application Platform | 7.3 | — |
| Netapp | Active Iq Unified Manager | All versions | — |
| Netapp | Management Services For Element Software And Netapp Hci | All versions | — |
| Netapp | Snapcenter Plug-In | All versions | — |
| Netapp | Element | All versions | — |
| Oracle | Access Manager | 11.1.2.3.0 | — |
| Oracle | Access Manager | 12.2.1.3.0 | — |
| Oracle | Access Manager | 12.2.1.4.0 | — |
| Oracle | Agile Engineering Data Management | 6.2.1.0 | — |
| Oracle | Agile Product Lifecycle Analytics | 3.6.1 | — |
| Oracle | Agile Product Lifecycle Management | 9.3.3 | — |
| Oracle | Agile Product Lifecycle Management | 9.3.6 | — |
| Oracle | Agile Product Lifecycle Management Integration Pack | 3.6 | — |
| Oracle | Airlines Data Model | 12.1.1.0.0 | — |
| Oracle | Airlines Data Model | 12.2.0.1.0 | — |
| Oracle | Application Express | 21.1.4 | — |
| Oracle | Application Performance Management | 13.4.1.0 | — |
| Oracle | Application Performance Management | 13.5.1.0 | — |
| Oracle | Application Testing Suite | 13.3.0.1 | — |
| Oracle | Argus Analytics | 8.2.1 | — |
| Oracle | Argus Analytics | 8.2.2 | — |
| Oracle | Argus Analytics | 8.2.3 | — |
| Oracle | Argus Analytics | 8.21 | — |
| Oracle | Argus Insight | 8.2.1 | — |
| Oracle | Argus Insight | 8.2.2 | — |
| Oracle | Argus Insight | 8.2.3 | — |
| Oracle | Argus Safety | 8.2.1 | — |
| Oracle | Argus Safety | 8.2.2 | — |
| Oracle | Argus Safety | 8.2.3 | — |
| Oracle | Banking Apis | 18.1 | — |
| Oracle | Banking Apis | 18.2 | — |
| Oracle | Banking Apis | 18.3 | — |
| Oracle | Banking Apis | 19.1 | — |
| Oracle | Banking Apis | 19.2 | — |
| Oracle | Banking Apis | 20.1 | — |
| Oracle | Banking Apis | 21.1 | — |
| Oracle | Banking Deposits And Lines Of Credit Servicing | 2.12.0 | — |
| Oracle | Banking Digital Experience | 17.2 | — |
| Oracle | Banking Digital Experience | 18.1 | — |
| Oracle | Banking Digital Experience | 18.3 | — |
| Oracle | Banking Digital Experience | 19.1 | — |
| Oracle | Banking Digital Experience | 19.2 | — |
Showing 50 of 412 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2020:0159Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0024/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0159Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0024/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10219?
How severe is CVE-2019-10219?
How do I fix CVE-2019-10219?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10213OpenShift Container Platform, versions 4.1 and 4.2, does not…6.5
- CVE-2019-10214The containers/image library used by the container tools Pod…5.9
- CVE-2019-10215Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a…6.1
- CVE-2019-10216In ghostscript before version 9.50, the .buildfont1 procedur…7.8
- CVE-2019-10217A flaw was found in ansible 2.8.0 before 2.8.4. Fields manag…6.5
- CVE-2019-10218A flaw was found in the samba client, all samba versions bef…6.5
- CVE-2019-1022An elevation of privilege exists in Windows Audio Service. A…7.8
- CVE-2019-10220Linux kernel CIFS implementation, version 4.9.0 is vulnerabl…8.8
- CVE-2019-10221A Reflected Cross Site Scripting vulnerability was found in …6.1
- CVE-2019-10222A flaw was found in the Ceph RGW configuration with Beast as…7.5
- CVE-2019-10223A security issue was discovered in the kube-state-metrics ve…6.5
- CVE-2019-10224A flaw has been found in 389-ds-base versions 1.4.x.x before…4.6
Are you affected by CVE-2019-10219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
