CVE-2019-10219
Last modified
CVE-2019-10219 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Hibernate Validator | < 6.0.18 | — |
| Redhat | Hibernate Validator | 6.1.0 | Alpha1 |
| Redhat | Fuse | 1.0 | — |
| Redhat | Jboss Data Grid | All versions | — |
| Redhat | Jboss Enterprise Application Platform | All versions | — |
| Redhat | Openshift Application Runtimes | All versions | — |
| Redhat | Single Sign-On | All versions | — |
| Redhat | Jboss Enterprise Application Platform | 7.2 | — |
| Redhat | Jboss Enterprise Application Platform | 7.3 | — |
| Netapp | Active Iq Unified Manager | All versions | — |
| Netapp | Management Services For Element Software And Netapp Hci | All versions | — |
| Netapp | Snapcenter Plug-In | All versions | — |
| Netapp | Element | All versions | — |
| Oracle | Access Manager | 11.1.2.3.0 | — |
| Oracle | Access Manager | 12.2.1.3.0 | — |
| Oracle | Access Manager | 12.2.1.4.0 | — |
| Oracle | Agile Engineering Data Management | 6.2.1.0 | — |
| Oracle | Agile Plm | 9.3.3 | — |
| Oracle | Agile Plm | 9.3.6 | — |
| Oracle | Agile Product Lifecycle Analytics | 3.6.1 | — |
| Oracle | Agile Product Lifecycle Management Integration Pack | 3.6 | — |
| Oracle | Airlines Data Model | 12.1.1.0.0 | — |
| Oracle | Airlines Data Model | 12.2.0.1.0 | — |
| Oracle | Application Express | 21.1.4 | — |
| Oracle | Application Performance Management | 13.4.1.0 | — |
| Oracle | Application Performance Management | 13.5.1.0 | — |
| Oracle | Application Testing Suite | 13.3.0.1 | — |
| Oracle | Argus Analytics | 8.2.1 | — |
| Oracle | Argus Analytics | 8.2.2 | — |
| Oracle | Argus Analytics | 8.2.3 | — |
| Oracle | Argus Analytics | 8.21 | — |
| Oracle | Argus Insight | 8.2.1 | — |
| Oracle | Argus Insight | 8.2.2 | — |
| Oracle | Argus Insight | 8.2.3 | — |
| Oracle | Argus Safety | 8.2.1 | — |
| Oracle | Argus Safety | 8.2.2 | — |
| Oracle | Argus Safety | 8.2.3 | — |
| Oracle | Banking Apis | 18.1 | — |
| Oracle | Banking Apis | 18.2 | — |
| Oracle | Banking Apis | 18.3 | — |
| Oracle | Banking Apis | 19.1 | — |
| Oracle | Banking Apis | 19.2 | — |
| Oracle | Banking Apis | 20.1 | — |
| Oracle | Banking Apis | 21.1 | — |
| Oracle | Banking Deposits And Lines Of Credit Servicing | 2.12.0 | — |
| Oracle | Banking Digital Experience | 17.2 | — |
| Oracle | Banking Digital Experience | 18.1 | — |
| Oracle | Banking Digital Experience | 18.3 | — |
| Oracle | Banking Digital Experience | 19.1 | — |
| Oracle | Banking Digital Experience | 19.2 | — |
Showing 50 of 414 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2020:0159Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0024/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0159Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0024/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10219?
How severe is CVE-2019-10219?
How do I fix CVE-2019-10219?
Are you affected by CVE-2019-10219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
