CVE-2019-10219

Aliases:GHSA-m8p2-495h-ccmh
Modified
Published: 08 Nov 2019, 14:46
Last modified:07 Jul 2025, 13:55

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.0 (cve.org)
EPSS Score
1.67% LOW
2% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

08 Nov 2019, 14:46
Published
Vulnerability first disclosed
07 Jul 2025, 13:55
Last Modified
Vulnerability information updated

Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v3.0MEDIUMScore: 6.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 1.67% Percentile: 82%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • hibernatehibernate-validator

    ≥ 6.0.0.Alpha1, ≤ 6.0.17.Final | ≥ 6.1.0.Alpha1, ≤ 6.1.0.Alpha6

  • org.hibernatehibernate-validator

    ≥ 6.1.0.Alpha1, < 6.1.0.Alpha6 | ≥ 6.0.0.Alpha1, < 6.0.18.Final

  • org.hibernate.validatorhibernate-validator

    ≥ 6.1.0.Alpha1, < 6.1.0.Alpha6 | ≥ 6.0.0.Alpha1, < 6.0.18.Final

  • netappactive_iq_unified_manager

    na

  • netappelement

    na

  • netappmanagement_services_for_element_software_and_netapp_hci

    na

  • netappsnapcenter_plug-in

    na

  • oracleaccess_manager

    11.1.2.3.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oracleagile_engineering_data_management

    6.2.1.0

  • oracleagile_plm

    9.3.3 | 9.3.6

  • oracleagile_product_lifecycle_analytics

    3.6.1

  • oracleagile_product_lifecycle_management_integration_pack

    3.6

  • oracleairlines_data_model

    12.1.1.0.0 | 12.2.0.1.0

  • oracleapplication_express

    21.1.4

  • oracleapplication_performance_management

    13.4.1.0 | 13.5.1.0

  • oracleapplication_testing_suite

    13.3.0.1

  • oracleargus_analytics

    8.2.1 | 8.2.2 | 8.2.3

  • oracleargus_insight

    8.2.1 | 8.2.2 | 8.2.3

  • oracleargus_safety

    8.2.1 | 8.2.2 | 8.2.3

  • oraclebanking_apis

    18.1 | 18.2 | 18.3 | 19.1 | 19.2 | 20.1 | 21.1

  • oraclebanking_deposits_and_lines_of_credit_servicing

    2.12.0

  • oraclebanking_digital_experience

    17.2 | 18.1 | 18.3 | 19.1 | 19.2 | 20.1 | 21.1

  • oraclebanking_enterprise_default_management

    2.6.2 | 2.7.0 | 2.7.1 | 2.10.0 | 2.12.0

  • oraclebanking_enterprise_default_managment

    ≥ 2.3.0, ≤ 2.4.0

  • oraclebanking_loans_servicing

    2.12.0

  • oraclebanking_party_management

    2.7.0

  • oraclebanking_platform

    ≥ 2.3.0, ≤ 2.4.1 | 2.6.2 | 2.7.0 | 2.7.1

  • oraclebi_publisher

    5.5.0.0.0 | 11.1.1.9.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oraclebig_data_spatial_and_graph

    23.1

  • oraclebusiness_activity_monitoring

    12.2.1.4.0

  • oraclebusiness_intelligence

    5.5.0.0.0 | 5.9.0.0.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oraclebusiness_process_management_suite

    12.2.1.3.0 | 12.2.1.4.0

  • oracleclinical

    5.2.1 | 5.2.2

  • oraclecommerce_guided_search

    11.3.2

  • oraclecommerce_platform

    ≥ 11.3.0, ≤ 11.3.2

  • oraclecommunications_application_session_controller

    3.9.0

  • oraclecommunications_billing_and_revenue_management

    12.0.0.3 | 12.0.0.4

  • oraclecommunications_billing_and_revenue_management_elastic_charging_engine

    11.3 | 12.0

  • oraclecommunications_calendar_server

    8.0.0.5.0 | 8.0.0.6.0

  • oraclecommunications_cloud_native_core_automated_test_suite

    1.8.0

  • oraclecommunications_cloud_native_core_binding_support_function

    1.9.0 | 1.10.0

  • oraclecommunications_cloud_native_core_console

    1.7.0

  • oraclecommunications_cloud_native_core_network_function_cloud_native_environment

    1.9.0

  • oraclecommunications_cloud_native_core_network_repository_function

    1.14.0

  • oraclecommunications_cloud_native_core_policy

    1.14.0

  • oraclecommunications_cloud_native_core_security_edge_protection_proxy

    1.5.0 | 1.6.0 | 1.15.0

  • oraclecommunications_cloud_native_core_service_communication_proxy

    1.14.0

  • oraclecommunications_cloud_native_core_unified_data_repository

    1.14.0

  • oraclecommunications_contacts_server

    8.0.0.3.0

  • oraclecommunications_converged_application_server_-_service_controller

    6.2

Showing first 50 affected entries in server-rendered view.

References (28)