{"id":"CVE-2019-10219","title":"A vulnerability was found in Hibernate-Validator","summary":"A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS a…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-79"],"vendor":"redhat","product":"hibernate_validator","affected":["hibernate_validator < 6.0.18","hibernate_validator = 6.1.0","fuse = 1.0","jboss_data_grid","jboss_enterprise_application_platform","openshift_application_runtimes","single_sign-on","jboss_enterprise_application_platform = 7.2","jboss_enterprise_application_platform = 7.3","active_iq_unified_manager","management_services_for_element_software_and_netapp_hci","snapcenter_plug-in","element","access_manager = 11.1.2.3.0","access_manager = 12.2.1.3.0","access_manager = 12.2.1.4.0","agile_engineering_data_management = 6.2.1.0","agile_plm = 9.3.3","agile_plm = 9.3.6","agile_product_lifecycle_analytics = 3.6.1","agile_product_lifecycle_management_integration_pack = 3.6","airlines_data_model = 12.1.1.0.0","airlines_data_model = 12.2.0.1.0","application_express = 21.1.4","application_performance_management = 13.4.1.0","application_performance_management = 13.5.1.0","application_testing_suite = 13.3.0.1","argus_analytics = 8.2.1","argus_analytics = 8.2.2","argus_analytics = 8.2.3","argus_analytics = 8.21","argus_insight = 8.2.1","argus_insight = 8.2.2","argus_insight = 8.2.3","argus_safety = 8.2.1","argus_safety = 8.2.2","argus_safety = 8.2.3","banking_apis = 18.1","banking_apis = 18.2","banking_apis = 18.3","banking_apis = 19.1","banking_apis = 19.2","banking_apis = 20.1","banking_apis = 21.1","banking_deposits_and_lines_of_credit_servicing = 2.12.0","banking_digital_experience = 17.2","banking_digital_experience = 18.1","banking_digital_experience = 18.3","banking_digital_experience = 19.1","banking_digital_experience = 19.2","banking_digital_experience = 20.1","banking_digital_experience = 21.1","banking_enterprise_default_management = 2.6.2","banking_enterprise_default_management = 2.7.0","banking_enterprise_default_management = 2.7.1","banking_enterprise_default_management = 2.10.0","banking_enterprise_default_management = 2.12.0","banking_enterprise_default_managment >= 2.3.0, <= 2.4.0","banking_loans_servicing = 2.12.0","banking_party_management = 2.7.0","banking_platform >= 2.3.0, <= 2.4.1","banking_platform = 2.6.2","banking_platform = 2.7.0","banking_platform = 2.7.1","bi_publisher = 5.5.0.0.0","bi_publisher = 11.1.1.9.0","bi_publisher = 12.2.1.3.0","bi_publisher = 12.2.1.4.0","big_data_spatial_and_graph = 23.1","business_activity_monitoring = 12.2.1.4.0","business_intelligence = 5.5.0.0.0","business_intelligence = 5.9.0.0.0","business_intelligence = 12.2.1.3.0","business_intelligence = 12.2.1.4.0","business_process_management_suite = 12.2.1.3.0","business_process_management_suite = 12.2.1.4.0","clinical = 5.2.1","clinical = 5.2.2","commerce_guided_search = 11.3.2","commerce_platform >= 11.3.0, <= 11.3.2","communications_application_session_controller = 3.9.0","communications_billing_and_revenue_management = 12.0.0.3","communications_billing_and_revenue_management = 12.0.0.4","communications_billing_and_revenue_management_elastic_charging_engine = 11.3","communications_billing_and_revenue_management_elastic_charging_engine = 12.0","communications_calendar_server = 8.0.0.5.0","communications_calendar_server = 8.0.0.6.0","communications_cloud_native_core_automated_test_suite = 1.8.0","communications_cloud_native_core_binding_support_function = 1.9.0","communications_cloud_native_core_binding_support_function = 1.10.0","communications_cloud_native_core_console = 1.7.0","communications_cloud_native_core_network_function_cloud_native_environment = 1.9.0","communications_cloud_native_core_network_repository_function = 1.14.0","communications_cloud_native_core_policy = 1.14.0","communications_cloud_native_core_security_edge_protection_proxy = 1.5.0","communications_cloud_native_core_security_edge_protection_proxy = 1.6.0","communications_cloud_native_core_security_edge_protection_proxy = 1.15.0","communications_cloud_native_core_service_communication_proxy = 1.14.0","communications_cloud_native_core_unified_data_repository = 1.14.0","communications_contacts_server = 8.0.0.3.0"],"patched":["hibernate_validator 6.0.18"],"published":"2019-11-08","updated":"2026-08-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-10219","references":[{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219","label":"secalert@redhat.com"},{"url":"https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee","label":"secalert@redhat.com"},{"url":"https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe","label":"secalert@redhat.com"},{"url":"https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219","label":"secalert@redhat.com"},{"url":"https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0024/","label":"secalert@redhat.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0024/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.02167,"epssPercentile":0.81239,"ingestedAt":"2026-08-21T15:18:35.127Z","exploits":{"github":2,"githubRepos":["https://github.com/shoucheng3/hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final","https://github.com/shoucheng3/hibernate__hibernate-validator_CVE-2019-10219_6_0_18_Final_fixed"],"checkedAt":"2026-09-21T15:23:39.995Z"},"exploitAvailable":true,"slug":"CVE-2019-10219","body":"## Overview\n\nA vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.\n\n## Affected\n\n- `hibernate_validator < 6.0.18`\n- `hibernate_validator = 6.1.0`\n- `fuse = 1.0`\n- `jboss_data_grid`\n- `jboss_enterprise_application_platform`\n- `openshift_application_runtimes`\n- `single_sign-on`\n- `jboss_enterprise_application_platform = 7.2`\n- `jboss_enterprise_application_platform = 7.3`\n- `active_iq_unified_manager`\n- `management_services_for_element_software_and_netapp_hci`\n- `snapcenter_plug-in`\n- `element`\n- `access_manager = 11.1.2.3.0`\n- `access_manager = 12.2.1.3.0`\n- `access_manager = 12.2.1.4.0`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_plm = 9.3.3`\n- `agile_plm = 9.3.6`\n- `agile_product_lifecycle_analytics = 3.6.1`\n- `agile_product_lifecycle_management_integration_pack = 3.6`\n- `airlines_data_model = 12.1.1.0.0`\n- `airlines_data_model = 12.2.0.1.0`\n- `application_express = 21.1.4`\n- `application_performance_management = 13.4.1.0`\n- `application_performance_management = 13.5.1.0`\n- `application_testing_suite = 13.3.0.1`\n- `argus_analytics = 8.2.1`\n- `argus_analytics = 8.2.2`\n- `argus_analytics = 8.2.3`\n- `argus_analytics = 8.21`\n- `argus_insight = 8.2.1`\n- `argus_insight = 8.2.2`\n- `argus_insight = 8.2.3`\n- `argus_safety = 8.2.1`\n- `argus_safety = 8.2.2`\n- `argus_safety = 8.2.3`\n- `banking_apis = 18.1`\n- `banking_apis = 18.2`\n- `banking_apis = 18.3`\n- `banking_apis = 19.1`\n- `banking_apis = 19.2`\n- `banking_apis = 20.1`\n- `banking_apis = 21.1`\n- `banking_deposits_and_lines_of_credit_servicing = 2.12.0`\n- `banking_digital_experience = 17.2`\n- `banking_digital_experience = 18.1`\n- `banking_digital_experience = 18.3`\n- `banking_digital_experience = 19.1`\n- `banking_digital_experience = 19.2`\n- `banking_digital_experience = 20.1`\n- `banking_digital_experience = 21.1`\n- `banking_enterprise_default_management = 2.6.2`\n- `banking_enterprise_default_management = 2.7.0`\n- `banking_enterprise_default_management = 2.7.1`\n- `banking_enterprise_default_management = 2.10.0`\n- `banking_enterprise_default_management = 2.12.0`\n- `banking_enterprise_default_managment >= 2.3.0, <= 2.4.0`\n- `banking_loans_servicing = 2.12.0`\n- `banking_party_management = 2.7.0`\n- `banking_platform >= 2.3.0, <= 2.4.1`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `bi_publisher = 5.5.0.0.0`\n- `bi_publisher = 11.1.1.9.0`\n- `bi_publisher = 12.2.1.3.0`\n- `bi_publisher = 12.2.1.4.0`\n- `big_data_spatial_and_graph = 23.1`\n- `business_activity_monitoring = 12.2.1.4.0`\n- `business_intelligence = 5.5.0.0.0`\n- `business_intelligence = 5.9.0.0.0`\n- `business_intelligence = 12.2.1.3.0`\n- `business_intelligence = 12.2.1.4.0`\n- `business_process_management_suite = 12.2.1.3.0`\n- `business_process_management_suite = 12.2.1.4.0`\n- `clinical = 5.2.1`\n- `clinical = 5.2.2`\n- `commerce_guided_search = 11.3.2`\n- `commerce_platform >= 11.3.0, <= 11.3.2`\n- `communications_application_session_controller = 3.9.0`\n- `communications_billing_and_revenue_management = 12.0.0.3`\n- `communications_billing_and_revenue_management = 12.0.0.4`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`\n- `communications_calendar_server = 8.0.0.5.0`\n- `communications_calendar_server = 8.0.0.6.0`\n- `communications_cloud_native_core_automated_test_suite = 1.8.0`\n- `communications_cloud_native_core_binding_support_function = 1.9.0`\n- `communications_cloud_native_core_binding_support_function = 1.10.0`\n- `communications_cloud_native_core_console = 1.7.0`\n- `communications_cloud_native_core_network_function_cloud_native_environment = 1.9.0`\n- `communications_cloud_native_core_network_repository_function = 1.14.0`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_cloud_native_core_security_edge_protection_proxy = 1.5.0`\n- `communications_cloud_native_core_security_edge_protection_proxy = 1.6.0`\n- `communications_cloud_native_core_security_edge_protection_proxy = 1.15.0`\n- `communications_cloud_native_core_service_communication_proxy = 1.14.0`\n- `communications_cloud_native_core_unified_data_repository = 1.14.0`\n- `communications_contacts_server = 8.0.0.3.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `hibernate_validator 6.0.18`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4454,"id":"CVE-2019-10219","ts":1788887180831,"field":"exploit_available","old":"false","new":"true"},{"seq":3337,"id":"CVE-2019-10219","ts":1788886299801,"field":"exploit_available","old":"true","new":"false"},{"seq":2192,"id":"CVE-2019-10219","ts":1788882969505,"field":"exploit_available","old":"false","new":"true"},{"seq":1221,"id":"CVE-2019-10219","ts":1788882375337,"field":"exploit_available","old":"true","new":"false"},{"seq":335,"id":"CVE-2019-10219","ts":1788881816092,"field":"exploit_available","old":"false","new":"true"}]}