CVE-2019-10219

MEDIUMCVSS 6.1/10EPSS 2.17%

Last modified

CVE-2019-10219 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. EPSS estimates a 2.17% chance of exploitation in the next 30 days.

Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
2.17%

79.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
RedhatHibernate Validator< 6.0.18
RedhatHibernate Validator6.1.0Alpha1
RedhatFuse1.0
RedhatJboss Data GridAll versions
RedhatJboss Enterprise Application PlatformAll versions
RedhatOpenshift Application RuntimesAll versions
RedhatSingle Sign-OnAll versions
RedhatJboss Enterprise Application Platform7.2
RedhatJboss Enterprise Application Platform7.3
NetappActive Iq Unified ManagerAll versions
NetappManagement Services For Element Software And Netapp HciAll versions
NetappSnapcenter Plug-InAll versions
NetappElementAll versions
OracleAccess Manager11.1.2.3.0
OracleAccess Manager12.2.1.3.0
OracleAccess Manager12.2.1.4.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.3
OracleAgile Plm9.3.6
OracleAgile Product Lifecycle Analytics3.6.1
OracleAgile Product Lifecycle Management Integration Pack3.6
OracleAirlines Data Model12.1.1.0.0
OracleAirlines Data Model12.2.0.1.0
OracleApplication Express21.1.4
OracleApplication Performance Management13.4.1.0
OracleApplication Performance Management13.5.1.0
OracleApplication Testing Suite13.3.0.1
OracleArgus Analytics8.2.1
OracleArgus Analytics8.2.2
OracleArgus Analytics8.2.3
OracleArgus Analytics8.21
OracleArgus Insight8.2.1
OracleArgus Insight8.2.2
OracleArgus Insight8.2.3
OracleArgus Safety8.2.1
OracleArgus Safety8.2.2
OracleArgus Safety8.2.3
OracleBanking Apis18.1
OracleBanking Apis18.2
OracleBanking Apis18.3
OracleBanking Apis19.1
OracleBanking Apis19.2
OracleBanking Apis20.1
OracleBanking Apis21.1
OracleBanking Deposits And Lines Of Credit Servicing2.12.0
OracleBanking Digital Experience17.2
OracleBanking Digital Experience18.1
OracleBanking Digital Experience18.3
OracleBanking Digital Experience19.1
OracleBanking Digital Experience19.2

Showing 50 of 414 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10219?
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
How severe is CVE-2019-10219?
CVE-2019-10219 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 2.17% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10219?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST