CVE-2019-10219

Published Nov 8, 2019

Last updated 9 hours ago

Overview

Description
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Source
secalert@redhat.com
NVD status
Modified
Products
hibernate_validator, fuse, jboss_data_grid, jboss_enterprise_application_platform, openshift_application_runtimes, single_sign-on, active_iq_unified_manager, management_services_for_element_software_and_netapp_hci, snapcenter_plug-in, element, access_manager, agile_engineering_data_management, agile_product_lifecycle_analytics, agile_product_lifecycle_management, agile_product_lifecycle_management_integration_pack, airlines_data_model, application_express, application_performance_management, application_testing_suite, argus_analytics, argus_insight, argus_safety, banking_apis, banking_deposits_and_lines_of_credit_servicing, banking_digital_experience, banking_enterprise_default_management, banking_enterprise_default_managment, banking_loans_servicing, banking_party_management, banking_platform, bi_publisher, big_data_spatial_and_graph, business_activity_monitoring, business_intelligence, business_process_management_suite, clinical, commerce_guided_search, commerce_platform, communications_application_session_controller, communications_billing_and_revenue_management, communications_billing_and_revenue_management_elastic_charging_engine, communications_calendar_server, communications_cloud_native_core_automated_test_suite, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_console, communications_cloud_native_core_network_function_cloud_native_environment, communications_cloud_native_core_network_repository_function, communications_cloud_native_core_policy, communications_cloud_native_core_security_edge_protection_proxy, communications_cloud_native_core_service_communication_proxy, communications_cloud_native_core_unified_data_repository, communications_contacts_server, communications_converged_application_server_-_service_controller, communications_convergence, communications_convergent_charging_controller, communications_data_model, communications_design_studio, communications_diameter_signaling_route, communications_eagle_application_processor, communications_instant_messaging_server, communications_interactive_session_recorder, communications_messaging_server, communications_metasolv_solution, communications_network_charging_and_control, communications_network_integrity, communications_offline_mediation_controller, communications_operations_monitor, communications_pricing_design_center, communications_service_broker, communications_services_gatekeeper, communications_session_border_controller, communications_unified_inventory_management, communications_webrtc_session_controller, data_integrator, database_server, demantra_demand_management, documaker, e-business_suite, enterprise_communications_broker, enterprise_data_quality, enterprise_manager_base_platform, enterprise_manager_ops_center, enterprise_session_border_controller, essbase, essbase_administration_services, financial_services_analytical_applications_infrastructure, financial_services_behavior_detection_platform, financial_services_enterprise_case_management, financial_services_foreign_account_tax_compliance_act_management, financial_services_model_management_and_governance, financial_services_trade-based_anti_money_laundering, flexcube_investor_servicing, flexcube_private_banking, fusion_middleware, fusion_middleware_mapviewer, goldengate, goldengate_application_adapters, graalvm, graph_server_and_client, health_sciences_clinical_development_analytics, health_sciences_inform_crf_submit, health_sciences_information_manager, healthcare_data_repository, healthcare_foundation, healthcare_translational_research, hospitality_cruise_shipboard_property_management_system, hospitality_opera_5_property_services, hospitality_reporting_and_analytics, hospitality_suite8, http_server, hyperion_financial_management, hyperion_ilearning, hyperion_infrastructure_technology, instantis_enterprisetrack, insurance_data_gateway, insurance_insbridge_rating_and_underwriting, insurance_policy_administration, insurance_policy_administration_j2ee, insurance_rules_palette, java_se, jd_edwards_enterpriseone_orchestrator, jdk, managed_file_transfer, mysql_cluster, mysql_connectors, mysql_server, mysql_workbench, nosql_database, oss_support_tools, peoplesoft_enterprise_cs_sa_integration_pack, peoplesoft_enterprise_peopletools, policy_automation, primavera_analytics, primavera_data_warehouse, primavera_gateway, primavera_p6_enterprise_project_portfolio_management, primavera_p6_professional_project_management, primavera_portfolio_management, primavera_unifier, rapid_planning, real-time_decision_server, real_user_experience_insight, rest_data_services, retail_allocation, retail_analytics, retail_assortment_planning, retail_back_office, retail_central_office, retail_customer_insights, retail_customer_management_and_segmentation_foundation, retail_eftlink, retail_extract_transform_and_load, retail_financial_integration, retail_fiscal_management, retail_integration_bus, retail_invoice_matching, retail_merchandising_system, retail_order_broker, retail_order_management_system, retail_point-of-sale, retail_predictive_application_server, retail_price_management, retail_returns_management, retail_service_backbone, retail_size_profile_optimization, retail_xstore_point_of_service, sd-wan_aware, sd-wan_edge, secure_backup, siebel_applications, spatial_studio, thesaurus_management_system, timesten_in-memory_database, utilities_framework, utilities_testing_accelerator, vm_virtualbox, webcenter_portal, weblogic_server, zfs_storage_appliance_kit, zfs_storage_application_integration_engineering_software, solaris, fujitsu_m10-1_firmware, fujitsu_m10-4_firmware, fujitsu_m10-4s_firmware, fujitsu_m12-1_firmware, fujitsu_m12-2_firmware, fujitsu_m12-2s_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

CVSS 3.0

Type
Secondary
Base score
6.5
Impact score
2.5
Exploitability score
3.9
Vector string
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

secalert@redhat.com
CWE-79
nvd@nist.gov
CWE-79

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.