GHSA-m8p2-495h-ccmh · Severity: medium · Ecosystem: maven — The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Conclusion & alert: CVE-2019-10219 is rated Moderate Risk (53.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.67%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-28 | 1.41% | 1.67% | +0.26% |
| 2 | 2025-12-27 | 1.67% | 1.41% | -0.26% |
| 3 | 2025-11-21 | — | 1.67% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 6.5 | 3.0 | MEDIUM |
|
3.9 | 2.5 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-m8p2-495h-ccmh · Severity: medium · Ecosystem: maven — The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2019-10219 unimportant priority: Debian including 2 source packages (libhibernate-validator-java, libhibernate-validator4-java), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5, resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-10219 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-10219 |
ubuntu
|
medium | CVE-2019-10219 medium priority: Ubuntu including 1 source packages (libhibernate-validator-java), 18 status rows across 18 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 10, needs-triage 7, DNE 1. | https://ubuntu.com/security/CVE-2019-10219 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| redhat | hibernate_validator | < 6.0.18 | cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha1:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha2:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha3:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha4:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha5:*:*:*:*:*:* |
| redhat | hibernate_validator | 6.1.0 | cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha6:*:*:*:*:*:* |
| redhat | fuse | 1.0 | cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:* |
| redhat | jboss_data_grid | — | cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:* |
| redhat | jboss_enterprise_application_platform | — | cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:* |
| redhat | openshift_application_runtimes | — | cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:* |
| redhat | single_sign-on | — | cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* |
| redhat | jboss_enterprise_application_platform | 7.2 | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:* |
| redhat | jboss_enterprise_application_platform | 7.3 | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| netapp | management_services_for_element_software_and_netapp_hci | — | cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:* |
| netapp | snapcenter_plug-in | — | cpe:2.3:a:netapp:snapcenter_plug-in:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | element | — | cpe:2.3:o:netapp:element:-:*:*:*:*:vcenter_server:*:* |
| oracle | access_manager | 11.1.2.3.0 | cpe:2.3:a:oracle:access_manager:11.1.2.3.0:*:*:*:*:*:*:* |
| oracle | access_manager | 12.2.1.3.0 | cpe:2.3:a:oracle:access_manager:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | access_manager | 12.2.1.4.0 | cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.2.1.0 | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.3 | cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.6 | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
| oracle | agile_product_lifecycle_analytics | 3.6.1 | cpe:2.3:a:oracle:agile_product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 | cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.6:*:*:*:*:e-business_suite:*:* |
| oracle | airlines_data_model | 12.1.1.0.0 | cpe:2.3:a:oracle:airlines_data_model:12.1.1.0.0:*:*:*:*:*:*:* |
| oracle | airlines_data_model | 12.2.0.1.0 | cpe:2.3:a:oracle:airlines_data_model:12.2.0.1.0:*:*:*:*:*:*:* |
| oracle | application_express | 21.1.4 | cpe:2.3:a:oracle:application_express:21.1.4:*:*:*:*:*:*:* |
| oracle | application_performance_management | 13.4.1.0 | cpe:2.3:a:oracle:application_performance_management:13.4.1.0:*:*:*:*:*:*:* |
| oracle | application_performance_management | 13.5.1.0 | cpe:2.3:a:oracle:application_performance_management:13.5.1.0:*:*:*:*:*:*:* |
| oracle | application_testing_suite | 13.3.0.1 | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* |
| oracle | argus_analytics | 8.2.1 | cpe:2.3:a:oracle:argus_analytics:8.2.1:*:*:*:*:*:*:* |
| oracle | argus_analytics | 8.2.2 | cpe:2.3:a:oracle:argus_analytics:8.2.2:*:*:*:*:*:*:* |
| oracle | argus_analytics | 8.2.3 | cpe:2.3:a:oracle:argus_analytics:8.2.3:*:*:*:*:*:*:* |
| oracle | argus_analytics | 8.21 | cpe:2.3:a:oracle:argus_analytics:8.21:*:*:*:*:*:*:* |
| oracle | argus_insight | 8.2.1 | cpe:2.3:a:oracle:argus_insight:8.2.1:*:*:*:*:*:*:* |
| oracle | argus_insight | 8.2.2 | cpe:2.3:a:oracle:argus_insight:8.2.2:*:*:*:*:*:*:* |
| oracle | argus_insight | 8.2.3 | cpe:2.3:a:oracle:argus_insight:8.2.3:*:*:*:*:*:*:* |
| oracle | argus_safety | 8.2.1 | cpe:2.3:a:oracle:argus_safety:8.2.1:*:*:*:*:*:*:* |
| oracle | argus_safety | 8.2.2 | cpe:2.3:a:oracle:argus_safety:8.2.2:*:*:*:*:*:*:* |
| oracle | argus_safety | 8.2.3 | cpe:2.3:a:oracle:argus_safety:8.2.3:*:*:*:*:*:*:* |
| oracle | banking_apis | 18.1 | cpe:2.3:a:oracle:banking_apis:18.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 18.2 | cpe:2.3:a:oracle:banking_apis:18.2:*:*:*:*:*:*:* |
| oracle | banking_apis | 18.3 | cpe:2.3:a:oracle:banking_apis:18.3:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.1 | cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.2 | cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:* |
| oracle | banking_apis | 20.1 | cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 21.1 | cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:* |
| oracle | banking_deposits_and_lines_of_credit_servicing | 2.12.0 | cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 17.2 | cpe:2.3:a:oracle:banking_digital_experience:17.2:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.1 | cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.3 | cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.1 | cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.2 | cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 20.1 | cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 21.1 | cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.6.2 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.6.2:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.7.0 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.7.1 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.1:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.10.0 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.12.0 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_managment | >= 2.3.0, <= 2.4.0 | cpe:2.3:a:oracle:banking_enterprise_default_managment:*:*:*:*:*:*:*:* |
| oracle | banking_loans_servicing | 2.12.0 | cpe:2.3:a:oracle:banking_loans_servicing:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_party_management | 2.7.0 | cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_platform | >= 2.3.0, <= 2.4.1 | cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.6.2 | cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.7.0 | cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.7.1 | cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:* |
| oracle | bi_publisher | 5.5.0.0.0 | cpe:2.3:a:oracle:bi_publisher:5.5.0.0.0:*:*:*:*:*:*:* |
| oracle | bi_publisher | 11.1.1.9.0 | cpe:2.3:a:oracle:bi_publisher:11.1.1.9.0:*:*:*:*:*:*:* |
| oracle | bi_publisher | 12.2.1.3.0 | cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | bi_publisher | 12.2.1.4.0 | cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | big_data_spatial_and_graph | 23.1 | cpe:2.3:a:oracle:big_data_spatial_and_graph:23.1:*:*:*:*:*:*:* |
| oracle | business_activity_monitoring | 12.2.1.4.0 | cpe:2.3:a:oracle:business_activity_monitoring:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | business_intelligence | 5.5.0.0.0 | cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:* |
| oracle | business_intelligence | 5.9.0.0.0 | cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* |
| oracle | business_intelligence | 12.2.1.3.0 | cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* |