Improper input validation in Oracle WebLogic Server - CVE-2019-10219

 

Improper input validation in Oracle WebLogic Server - CVE-2019-10219

Published: January 18, 2022


Vulnerability identifier: #VU59717
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10219
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the Web Services (JBoss Enterprise Application Platform) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.


Affected software

Oracle WebLogic Server
IBM Tivoli Network Manager (ITNM)
Cloudera Data Platform Private Cloud Base for IBM
openEuler
Netcool Operations Insight
IBM TRIRIGA Application Platform
hibernate-validator-performance
hibernate-validator-javadoc
hibernate-validator-cdi
hibernate-validator-annotation-processor
hibernate-validator-test-utils
hibernate-validator-parent
hibernate-validator
Red Hat Single Sign-On

How to mitigate CVE-2019-10219

Install updates from vendor's website.

IBM Tivoli Network Manager (ITNM) - update to 4.2.0.15
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Netcool Operations Insight - update to 1.6.9
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
hibernate-validator-performance - update to 5.2.4-4
hibernate-validator-javadoc - update to 5.2.4-4
hibernate-validator-cdi - update to 5.2.4-4
hibernate-validator-annotation-processor - update to 5.2.4-4
hibernate-validator-test-utils - update to 5.2.4-4
hibernate-validator-parent - update to 5.2.4-4
hibernate-validator - update to 5.2.4-4
Red Hat Single Sign-On - update to 7.3.6

External References

Related Security Bulletins