Disclosure summary
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Source-reported weakness categories
CWE-79
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2019-10219
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| redhat | hibernate_validator | * {"versionEndExcluding":"6.0.18"} |
| redhat | hibernate_validator | 6.1.0 |
| redhat | hibernate_validator | 6.1.0 |
| redhat | hibernate_validator | 6.1.0 |
| redhat | hibernate_validator | 6.1.0 |
| redhat | hibernate_validator | 6.1.0 |
| redhat | hibernate_validator | 6.1.0 |
| redhat | fuse | 1.0 |
| redhat | jboss_data_grid | - |
| redhat | jboss_enterprise_application_platform | - |
| redhat | openshift_application_runtimes | - |
| redhat | single_sign-on | - |
| redhat | jboss_enterprise_application_platform | 7.2 |
| redhat | jboss_enterprise_application_platform | 7.3 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | management_services_for_element_software_and_netapp_hci | - |
| netapp | snapcenter_plug-in | - |
| netapp | element | - |
| oracle | access_manager | 11.1.2.3.0 |
| oracle | access_manager | 12.2.1.3.0 |
| oracle | access_manager | 12.2.1.4.0 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | agile_product_lifecycle_analytics | 3.6.1 |
| oracle | agile_product_lifecycle_management | 9.3.3 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | agile_product_lifecycle_management_integration_pack | 3.6 |
| oracle | airlines_data_model | 12.1.1.0.0 |
| oracle | airlines_data_model | 12.2.0.1.0 |
| oracle | application_express | 21.1.4 |
| oracle | application_performance_management | 13.4.1.0 |
| oracle | application_performance_management | 13.5.1.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | argus_analytics | 8.2.1 |
| oracle | argus_analytics | 8.2.2 |
| oracle | argus_analytics | 8.2.3 |
| oracle | argus_analytics | 8.21 |
| oracle | argus_insight | 8.2.1 |
| oracle | argus_insight | 8.2.2 |
| oracle | argus_insight | 8.2.3 |
| oracle | argus_safety | 8.2.1 |
| oracle | argus_safety | 8.2.2 |
| oracle | argus_safety | 8.2.3 |
| oracle | banking_apis | 18.1 |
| oracle | banking_apis | 18.2 |
| oracle | banking_apis | 18.3 |
| oracle | banking_apis | 19.1 |
| oracle | banking_apis | 19.2 |
| oracle | banking_apis | 20.1 |
| oracle | banking_apis | 21.1 |
| oracle | banking_deposits_and_lines_of_credit_servicing | 2.12.0 |
| oracle | banking_digital_experience | 17.2 |
| oracle | banking_digital_experience | 18.1 |
| oracle | banking_digital_experience | 18.3 |
| oracle | banking_digital_experience | 19.1 |
| oracle | banking_digital_experience | 19.2 |
| oracle | banking_digital_experience | 20.1 |
| oracle | banking_digital_experience | 21.1 |
| oracle | banking_enterprise_default_management | 2.6.2 |
| oracle | banking_enterprise_default_management | 2.7.0 |
| oracle | banking_enterprise_default_management | 2.7.1 |
| oracle | banking_enterprise_default_management | 2.10.0 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_enterprise_default_managment | * {"versionStartIncluding":"2.3.0","versionEndIncluding":"2.4.0"} |
| oracle | banking_loans_servicing | 2.12.0 |
| oracle | banking_party_management | 2.7.0 |
| oracle | banking_platform | * {"versionStartIncluding":"2.3.0","versionEndIncluding":"2.4.1"} |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | bi_publisher | 5.5.0.0.0 |
| oracle | bi_publisher | 11.1.1.9.0 |
| oracle | bi_publisher | 12.2.1.3.0 |
| oracle | bi_publisher | 12.2.1.4.0 |
| oracle | big_data_spatial_and_graph | 23.1 |
| oracle | business_activity_monitoring | 12.2.1.4.0 |
| oracle | business_intelligence | 5.5.0.0.0 |
| oracle | business_intelligence | 5.9.0.0.0 |
| oracle | business_intelligence | 12.2.1.3.0 |
| oracle | business_intelligence | 12.2.1.4.0 |
| oracle | business_process_management_suite | 12.2.1.3.0 |
| oracle | business_process_management_suite | 12.2.1.4.0 |
| oracle | clinical | 5.2.1 |
| oracle | clinical | 5.2.2 |
| oracle | commerce_guided_search | 11.3.2 |
| oracle | commerce_platform | * {"versionStartIncluding":"11.3.0","versionEndIncluding":"11.3.2"} |
| oracle | communications_application_session_controller | 3.9.0 |
| oracle | communications_billing_and_revenue_management | 12.0.0.3 |
| oracle | communications_billing_and_revenue_management | 12.0.0.4 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 11.3 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0 |
| oracle | communications_calendar_server | 8.0.0.5.0 |
| oracle | communications_calendar_server | 8.0.0.6.0 |
| oracle | communications_cloud_native_core_automated_test_suite | 1.8.0 |
| oracle | communications_cloud_native_core_binding_support_function | 1.9.0 |
| oracle | communications_cloud_native_core_binding_support_function | 1.10.0 |
| oracle | communications_cloud_native_core_console | 1.7.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.9.0 |
| oracle | communications_cloud_native_core_network_repository_function | 1.14.0 |
Showing 100 associations; open the original for the complete set.
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- github.com
- github.com
- github.com
- github.com
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- security.netapp.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- access.redhat.com — Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- github.com
- github.com
- github.com
- github.com
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- security.netapp.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
PUBLISHED 2019-11-08T10:15:11-05:00
MODIFIED 2026-10-08T18:16:49-04:00
INGESTED 2026-10-10T20:50:18-04:00