A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
History
21 Nov 2024, 04:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/errata/RHSA-2020:0159Â - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0160Â - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0161Â - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0164Â - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0445Â - Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219Â - Issue Tracking, Third Party Advisory | |
References | () https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3EÂ - | |
References | () https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3EÂ - | |
References | () https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3EÂ - | |
References | () https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3EÂ - | |
References | () https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3EÂ - | |
References | () https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3EÂ - | |
References | () https://security.netapp.com/advisory/ntap-20220210-0024/Â - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory |
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-11-08 15:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10219
Mitre link : CVE-2019-10219
CVE.ORG link : CVE-2019-10219
JSON object : View
Products Affected
oracle
- communications_offline_mediation_controller
- insurance_rules_palette
- business_intelligence
- http_server
- banking_enterprise_default_management
- instantis_enterprisetrack
- agile_product_lifecycle_analytics
- communications_cloud_native_core_security_edge_protection_proxy
- retail_point-of-sale
- communications_services_gatekeeper
- e-business_suite
- vm_virtualbox
- fujitsu_m12-1
- financial_services_model_management_and_governance
- retail_allocation
- retail_xstore_point_of_service
- application_testing_suite
- communications_cloud_native_core_network_repository_function
- banking_digital_experience
- communications_data_model
- managed_file_transfer
- fujitsu_m10-4
- communications_convergence
- oss_support_tools
- zfs_storage_appliance_kit
- essbase
- banking_party_management
- communications_contacts_server
- demantra_demand_management
- thesaurus_management_system
- webcenter_portal
- business_process_management_suite
- fujitsu_m12-2
- documaker
- communications_pricing_design_center
- jd_edwards_enterpriseone_orchestrator
- mysql_cluster
- fujitsu_m12-2_firmware
- data_integrator
- peoplesoft_enterprise_peopletools
- primavera_portfolio_management
- banking_apis
- hyperion_infrastructure_technology
- argus_insight
- fujitsu_m12-1_firmware
- communications_cloud_native_core_network_function_cloud_native_environment
- insurance_data_gateway
- sd-wan_edge
- communications_billing_and_revenue_management_elastic_charging_engine
- communications_network_charging_and_control
- primavera_data_warehouse
- policy_automation
- retail_order_broker
- primavera_p6_enterprise_project_portfolio_management
- communications_webrtc_session_controller
- solaris
- java_se
- financial_services_analytical_applications_infrastructure
- mysql_server
- peoplesoft_enterprise_people_tools
- financial_services_behavior_detection_platform
- communications_metasolv_solution
- database_server
- nosql_database
- healthcare_foundation
- communications_cloud_native_core_console
- fujitsu_m10-4s
- hospitality_suite8
- retail_invoice_matching
- commerce_platform
- sd-wan_aware
- utilities_framework
- graalvm
- rest_data_services
- goldengate_application_adapters
- argus_analytics
- flexcube_private_banking
- commerce_guided_search
- retail_central_office
- banking_enterprise_default_managment
- communications_cloud_native_core_binding_support_function
- communications_cloud_native_core_automated_test_suite
- retail_financial_integration
- enterprise_manager_ops_center
- communications_cloud_native_core_unified_data_repository
- clinical
- hyperion_financial_management
- siebel_applications
- communications_diameter_signaling_route
- real_user_experience_insight
- hospitality_cruise_shipboard_property_management_system
- rapid_planning
- weblogic_server
- communications_cloud_native_core_policy
- primavera_unifier
- fujitsu_m10-4_firmware
- big_data_spatial_and_graph
- communications_eagle_application_processor
- health_sciences_clinical_development_analytics
- retail_customer_insights
- enterprise_communications_broker
- mysql_workbench
- fujitsu_m10-1_firmware
- hospitality_reporting_and_analytics
- retail_back_office
- airlines_data_model
- retail_assortment_planning
- communications_design_studio
- communications_session_border_controller
- communications_converged_application_server_-_service_controller
- health_sciences_information_manager
- insurance_policy_administration_j2ee
- retail_extract_transform_and_load
- communications_cloud_native_core_service_communication_proxy
- communications_operations_monitor
- enterprise_manager_base_platform
- access_manager
- insurance_policy_administration
- fujitsu_m10-1
- bi_publisher
- banking_deposits_and_lines_of_credit_servicing
- real-time_decision_server
- retail_returns_management
- communications_network_integrity
- communications_instant_messaging_server
- retail_price_management
- agile_product_lifecycle_management_integration_pack
- banking_platform
- banking_loans_servicing
- jdk
- retail_merchandising_system
- agile_plm
- retail_integration_bus
- secure_backup
- fujitsu_m10-4s_firmware
- retail_order_management_system
- spatial_studio
- retail_size_profile_optimization
- application_express
- communications_unified_inventory_management
- retail_predictive_application_server
- primavera_analytics
- enterprise_data_quality
- essbase_administration_services
- hyperion_ilearning
- financial_services_trade-based_anti_money_laundering
- timesten_in-memory_database
- zfs_storage_application_integration_engineering_software
- goldengate
- insurance_insbridge_rating_and_underwriting
- hospitality_opera_5_property_services
- fujitsu_m12-2s_firmware
- enterprise_session_border_controller
- healthcare_translational_research
- fujitsu_m12-2s
- communications_service_broker
- primavera_p6_professional_project_management
- fusion_middleware
- retail_fiscal_management
- argus_safety
- communications_interactive_session_recorder
- financial_services_foreign_account_tax_compliance_act_management
- mysql_connectors
- business_activity_monitoring
- communications_application_session_controller
- healthcare_data_repository
- financial_services_enterprise_case_management
- retail_service_backbone
- application_performance_management
- retail_eftlink
- peoplesoft_enterprise_cs_sa_integration_pack
- retail_analytics
- graph_server_and_client
- communications_convergent_charging_controller
- utilities_testing_accelerator
- communications_messaging_server
- health_sciences_inform_crf_submit
- flexcube_investor_servicing
- communications_billing_and_revenue_management
- agile_engineering_data_management
- fusion_middleware_mapviewer
- retail_customer_management_and_segmentation_foundation
- communications_calendar_server
- primavera_gateway
redhat
- openshift_application_runtimes
- hibernate_validator
- single_sign-on
- jboss_data_grid
- jboss_enterprise_application_platform
- fuse
- enterprise_linux
netapp
- snapcenter_plug-in
- management_services_for_element_software_and_netapp_hci
- element
- active_iq_unified_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')