MEDIUM · 6.1

CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This...

Vulnerability Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
RedhatHibernate Validator< 6.0.18
RedhatFuse1.0
RedhatJboss Data Grid-
RedhatJboss Enterprise Application Platform-
RedhatOpenshift Application Runtimes-
RedhatSingle Sign-On-
RedhatEnterprise Linux6.0
NetappActive Iq Unified Manager-
NetappManagement Services For Element Software And Netapp Hci-
NetappSnapcenter Plug-In-
NetappElement-
OracleAccess Manager11.1.2.3.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.3
OracleAgile Product Lifecycle Analytics3.6.1
OracleAgile Product Lifecycle Management Integration Pack3.6
OracleAirlines Data Model12.1.1.0.0
OracleApplication Express21.1.4
OracleApplication Performance Management13.4.1.0
OracleApplication Testing Suite13.3.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10219?

CVE-2019-10219 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This...

How severe is CVE-2019-10219?

CVE-2019-10219 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10219?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Hibernate Validator, Redhat Fuse, Redhat Jboss Data Grid, Redhat Jboss Enterprise Application Platform, Redhat Openshift Application Runtimes.