cbcvebase.
CVE-2019-10219
published 2019-11-08

CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Affected

404 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibhibernate-validator-java
debianlibhibernate-validator4-java
hibernatehibernate-validator6.0.0.Alpha1 – 6.0.17.Final
hibernatehibernate-validator6.1.0.Alpha1 – 6.1.0.Alpha6
oracleaccess_manager
oracleaccess_manager
oracleaccess_manager
oracleagile_engineering_data_management
oracleagile_plm
oracleagile_plm
oracleagile_product_lifecycle_analytics
oracleagile_product_lifecycle_management_integration_pack
oracleairlines_data_model
oracleairlines_data_model
oracleapplication_express
oracleapplication_performance_management
oracleapplication_performance_management
oracleapplication_testing_suite
oracleargus_analytics
oracleargus_analytics
oracleargus_analytics
oracleargus_analytics
oracleargus_insight
oracleargus_insight
oracleargus_insight

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM