6.5

CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatHibernate Validator Version < 6.0.18
RedhatHibernate Validator Version6.1.0 Updatealpha1
RedhatHibernate Validator Version6.1.0 Updatealpha2
RedhatHibernate Validator Version6.1.0 Updatealpha3
RedhatHibernate Validator Version6.1.0 Updatealpha4
RedhatHibernate Validator Version6.1.0 Updatealpha5
RedhatHibernate Validator Version6.1.0 Updatealpha6
RedhatFuse Version1.0
RedhatJboss Data Grid Version- SwEditiontext-only
RedhatJboss Enterprise Application Platform Version- SwEditiontext-only
RedhatOpenshift Application Runtimes Version- SwEditiontext-only
RedhatSingle Sign-on Version- SwEditiontext-only
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappSnapcenter Plug-in Version- SwPlatformvmware_vsphere
NetappElement Version- SwPlatformvcenter_server
OracleAccess Manager Version11.1.2.3.0
OracleAccess Manager Version12.2.1.3.0
OracleAccess Manager Version12.2.1.4.0
OracleAgile Plm Version9.3.3
OracleAgile Plm Version9.3.6
OracleAgile Product Lifecycle Management Integration Pack Version3.6 SwPlatforme-business_suite
OracleAirlines Data Model Version12.1.1.0.0
OracleAirlines Data Model Version12.2.0.1.0
OracleApplication Express Version21.1.4
OracleApplication Testing Suite Version13.3.0.1
OracleArgus Analytics Version8.2.1
OracleArgus Analytics Version8.2.2
OracleArgus Analytics Version8.2.3
OracleArgus Analytics Version8.21
OracleArgus Insight Version8.2.1
OracleArgus Insight Version8.2.2
OracleArgus Insight Version8.2.3
OracleArgus Safety Version8.2.1
OracleArgus Safety Version8.2.2
OracleArgus Safety Version8.2.3
OracleBanking Apis Version18.1
OracleBanking Apis Version18.2
OracleBanking Apis Version18.3
OracleBanking Apis Version19.1
OracleBanking Apis Version19.2
OracleBanking Apis Version20.1
OracleBanking Apis Version21.1
OracleBanking Enterprise Default Managment Version >= 2.3.0 <= 2.4.0
OracleBanking Loans Servicing Version2.12.0
OracleBanking Party Management Version2.7.0
OracleBanking Platform Version >= 2.3.0 <= 2.4.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBi Publisher Version5.5.0.0.0
OracleBi Publisher Version11.1.1.9.0
OracleBi Publisher Version12.2.1.3.0
OracleBi Publisher Version12.2.1.4.0
OracleBusiness Activity Monitoring Version12.2.1.4.0
OracleBusiness Intelligence Version5.5.0.0.0 SwEditionenterprise
OracleBusiness Intelligence Version5.9.0.0.0 SwEditionenterprise
OracleBusiness Intelligence Version12.2.1.3.0 SwEditionenterprise
OracleBusiness Intelligence Version12.2.1.4.0 SwEditionenterprise
OracleClinical Version5.2.1
OracleClinical Version5.2.2
OracleCommerce Guided Search Version11.3.2
OracleCommerce Platform Version >= 11.3.0 <= 11.3.2
OracleCommunications Calendar Server Version8.0.0.5.0
OracleCommunications Calendar Server Version8.0.0.6.0
OracleCommunications Contacts Server Version8.0.0.3.0
OracleCommunications Convergence Version3.0.2.2.0
OracleCommunications Convergent Charging Controller Version >= 12.0.1.0.0 <= 12.0.4.0.0
OracleCommunications Data Model Version11.3.2.1.0
OracleCommunications Data Model Version11.3.2.2.0
OracleCommunications Data Model Version11.3.2.3.0
OracleCommunications Data Model Version12.1.0.1.0
OracleCommunications Data Model Version12.1.2.0.0
OracleCommunications Diameter Signaling Route Version >= 8.0.0.0 <= 8.5.1.0
OracleCommunications Network Charging And Control Version >= 12.0.1.0.0 <= 12.0.4.0.0
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleDatabase Server Version12.1.0.1
OracleDatabase Server Version12.1.0.2
OracleDatabase Server Version19c
OracleDatabase Server Version21c
OracleDemantra Demand Management Version >= 12.2.6 <= 12.2.11
OracleDocumaker Version >= 12.6.0 <= 12.6.4
OracleE-business Suite Version >= 12.2.3 <= 12.2.11
OracleEnterprise Data Quality Version12.2.1.3.0
OracleEnterprise Data Quality Version12.2.1.4.0
OracleEssbase Version < 11.1.2.4.47
OracleEssbase Version >= 21.0 < 21.3
OracleEssbase Version11.1.2.4.47
OracleEssbase Administration Services Version < 11.1.2.4.47
OracleEssbase Administration Services Version11.1.2.4.47
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.7 SwEditionenterprise
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.8 SwEditionenterprise
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleFusion Middleware Version12.2.1.3.0
OracleFusion Middleware Version12.2.1.4.0
OracleFusion Middleware Mapviewer Version12.2.1.4.0
OracleGoldengate Version < 12.3.0.1
OracleGoldengate Version >= 19.0.0 < 19.1.0.0.220118
OracleGoldengate Version >= 21.0.0 < 21.5.0.0.220118
OracleGoldengate Application Adapters Version19.1.0.0.0
OracleGraalvm Version20.3.4 SwEditionenterprise
OracleGraalvm Version21.3.0 SwEditionenterprise
OracleGraph Server And Client Version < 21.4
OracleHealthcare Foundation Version >= 7.3.0.0 <= 7.3.0.2
OracleHealthcare Foundation Version >= 8.0.0 <= 8.0.2
OracleHealthcare Foundation Version8.1.0
OracleHealthcare Foundation Version8.1.1
OracleHospitality Suite8 Version8.10.2
OracleHospitality Suite8 Version8.11.0
OracleHospitality Suite8 Version8.12.0
OracleHospitality Suite8 Version8.13.0
OracleHospitality Suite8 Version8.14.0
OracleHTTP Server Version12.2.1.3.0
OracleHTTP Server Version12.2.1.4.0
OracleHyperion Ilearning Version6.2
OracleHyperion Ilearning Version6.3
OracleInsurance Data Gateway Version11.0.2
OracleInsurance Data Gateway Version11.1.0
OracleInsurance Data Gateway Version11.2.7
OracleInsurance Data Gateway Version11.3.0
OracleInsurance Data Gateway Version11.3.1
OracleInsurance Policy Administration J2ee Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version10.2.0
OracleInsurance Rules Palette Version10.2.4
OracleInsurance Rules Palette Version11.0.2
OracleInsurance Rules Palette Version11.3.1
OracleJava Se Version7u321
OracleJava Se Version8u311
OracleJava Se Version17.1
OracleJdk Version11.0.13
OracleManaged File Transfer Version12.2.1.3.0
OracleManaged File Transfer Version12.2.1.4.0
OracleMysql Cluster Version < 7.4.34
OracleMysql Cluster Version >= 7.5.0 < 7.5.24
OracleMysql Cluster Version >= 7.6.0 < 7.6.20
OracleMysql Cluster Version >= 8.0.0 < 8.0.27
OracleMysql Connectors Version < 8.0.27
OracleMysql Connectors Version8.0.27
OracleMysql Server Version < 5.7.36
OracleMysql Server Version >= 8.0.0 < 8.0.27
OracleMysql Server Version5.7.36
OracleMysql Workbench Version < 8.0.27
OracleNosql Database Version < 21.1.12
OracleOss Support Tools Version < 2.12.42
OraclePolicy Automation Version >= 12.2.0 <= 12.2.24
OraclePolicy Automation Version10.4.7
OraclePrimavera Analytics Version18.8.3.3
OraclePrimavera Analytics Version19.12.11.1
OraclePrimavera Analytics Version20.12.12.0
OraclePrimavera Data Warehouse Version18.8.3.3
OraclePrimavera Data Warehouse Version19.12.11.1
OraclePrimavera Data Warehouse Version20.12.12.0
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.13
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.12
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Gateway Version21.12.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 17.12.0.0 <= 17.12.0.0-17.12.20.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 18.8.0.0 <= 18.8.24.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.18.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.12.0
OraclePrimavera P6 Professional Project Management Version >= 17.12.0.0 <= 17.12.20.0
OraclePrimavera P6 Professional Project Management Version >= 18.8.0.0 <= 18.8.24.0
OraclePrimavera P6 Professional Project Management Version >= 19.12.0.0 <= 19.12.17.0
OraclePrimavera P6 Professional Project Management Version >= 20.12.0.0 <= 20.12.9.0
OraclePrimavera Portfolio Management Version >= 18.0.0.0 <= 18.0.3.0
OraclePrimavera Portfolio Management Version >= 19.0.0.0 <= 19.0.1.2
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRapid Planning Version >= 12.2.6 <= 12.2.11
OracleReal-time Decision Server Version3.2.0.0
OracleReal User Experience Insight Version13.4.1.0
OracleReal User Experience Insight Version13.5.1.0
OracleRest Data Services Version21.2.4 SwEdition-
OracleRetail Allocation Version14.1.3.2
OracleRetail Allocation Version15.0.3.1
OracleRetail Allocation Version16.0.3
OracleRetail Allocation Version19.0.1
OracleRetail Analytics Version >= 16.0.0 <= 16.0.2
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Customer Insights Version >= 16.0.0 <= 16.0.2
OracleRetail Eftlink Version16.0.3
OracleRetail Eftlink Version17.0.2
OracleRetail Eftlink Version18.0.1
OracleRetail Eftlink Version19.0.1
OracleRetail Eftlink Version20.0.1
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Integration Bus Version >= 16.0.1 <= 16.0.3
OracleRetail Integration Bus Version13.0
OracleRetail Integration Bus Version14.1.3.0
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version19.0.0
OracleRetail Integration Bus Version19.0.1
OracleRetail Invoice Matching Version15.0.3
OracleRetail Invoice Matching Version16.0.3
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.1
OracleRetail Point-of-sale Version14.1
OracleRetail Price Management Version14.0.4
OracleRetail Price Management Version14.1.3
OracleRetail Price Management Version15.0.3
OracleRetail Price Management Version16.0.3
OracleRetail Service Backbone Version >= 16.0.1 <= 16.0.3
OracleRetail Service Backbone Version14.1.3.0
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version19.0.0
OracleRetail Service Backbone Version19.0.1
OracleSd-wan Aware Version8.2
OracleSd-wan Edge Version9.0
OracleSd-wan Edge Version9.1
OracleSecure Backup Version18.1.0.1.0
OracleSiebel Applications Version < 21.12
OracleSpatial Studio Version21.2.1
OracleTimesten In-memory Database Version < 11.2.2.8.27
OracleTimesten In-memory Database Version >= 21.0.0 < 21.1.1.1.0
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
OracleVm Virtualbox Version < 6.1.32
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWeblogic Server Version12.1.3.0.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
OracleSolaris Version10
OracleSolaris Version11
OracleFujitsu M10-1 Firmware Version-
   OracleFujitsu M10-1 Version-
OracleFujitsu M10-4 Firmware Version-
   OracleFujitsu M10-4 Version-
OracleFujitsu M10-4s Firmware Version-
   OracleFujitsu M10-4s Version-
OracleFujitsu M12-1 Firmware Version-
   OracleFujitsu M12-1 Version-
OracleFujitsu M12-2 Firmware Version-
   OracleFujitsu M12-2 Version-
OracleFujitsu M12-2s Firmware Version-
   OracleFujitsu M12-2s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.816
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
secalert@redhat.com 6.5 3.9 2.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.