Improper input validation in Oracle WebLogic Server - CVE-2019-10219
Published: January 18, 2022
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Web Services (JBoss Enterprise Application Platform) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
Affected software
IBM Tivoli Network Manager (ITNM)
Cloudera Data Platform Private Cloud Base for IBM
openEuler
Netcool Operations Insight
IBM TRIRIGA Application Platform
hibernate-validator-performance
hibernate-validator-javadoc
hibernate-validator-cdi
hibernate-validator-annotation-processor
hibernate-validator-test-utils
hibernate-validator-parent
hibernate-validator
Red Hat Single Sign-On
How to mitigate CVE-2019-10219
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Netcool Operations Insight - update to 1.6.9
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
hibernate-validator-performance - update to 5.2.4-4
hibernate-validator-javadoc - update to 5.2.4-4
hibernate-validator-cdi - update to 5.2.4-4
hibernate-validator-annotation-processor - update to 5.2.4-4
hibernate-validator-test-utils - update to 5.2.4-4
hibernate-validator-parent - update to 5.2.4-4
hibernate-validator - update to 5.2.4-4
Red Hat Single Sign-On - update to 7.3.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM Tivoli Network Manager
- Improper input validation in IBM TRIRIGA Application Platform
- Multiple vulnerabilities in Netcool Operations Insight
- openEuler update for hibernate-validator
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)