Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.0Report Generated On : Wed, 3 Mar 2021 21:10:39 +0100Dependencies Scanned : 64 (61 unique)Vulnerable Dependencies : 7 Vulnerabilities Found : 46Vulnerabilities Suppressed : 0... NVD CVE Checked : 2021-03-03T18:17:15NVD CVE Modified : 2021-03-03T16:02:16VersionCheckOn : 2021-03-03T08:29:07Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies XML-APIS-2.5.0.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/XML-APIS/XML-APIS/2.5.0/XML-APIS-2.5.0.jarMD5: d96b62c9d7c2a81efd1986b59582e4e1SHA1: 5f3baec73262ebebc87a457fb24012bedb6f0ca6SHA256: 00e7ff4fb2f424bb3c6031b6e7ad03c2badf7af08c1798c8ede6a5d7b7843520Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor pom groupid XML-APIS Highest Vendor pom artifactid XML-APIS Low Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor jar package name apache Highest Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor jar package name xml Highest Vendor file name XML-APIS High Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Product jar package name sax Highest Product pom groupid XML-APIS Highest Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.transform Medium Product jar package name xmlcommons Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product jar package name javax Highest Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product jar package name dom Highest Product jar package name version Highest Product jar package name w3c Highest Product jar package name xml Highest Product jar package name transform Highest Product pom artifactid XML-APIS Highest Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product jar package name apache Highest Product jar package name document Highest Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium Product file name XML-APIS High Version file version 2.5.0 High Version pom version 2.5.0 Highest
XMLEditor-2.2.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/XMLEditor/XMLEditor/2.2/XMLEditor-2.2.jarMD5: 4a4a0b6d61460d738a469ad200809624SHA1: 0b6ed34aa9b29b3e093ede285d08f6bce7128504SHA256: a84c1f3cdd1d38bdea7fa1513c152b50957eef17bc7d42f585d2c2dc31b9663dReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid XMLEditor Low Vendor jar package name xmleditor Highest Vendor jar package name fg Low Vendor pom groupid XMLEditor Highest Vendor file name XMLEditor High Product pom artifactid XMLEditor Highest Product jar package name xmleditor Highest Product pom groupid XMLEditor Highest Product file name XMLEditor High Version pom version 2.2 Highest Version file version 2.2 High
Xerces-2.5.0.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/Xerces/Xerces/2.5.0/Xerces-2.5.0.jarMD5: 17c7b058d32d6df45456e1728a299ba1SHA1: c0468bac6d11a07ffc69506003cfedc0ce54e172SHA256: d1ff701c93fdd4838b95ccef54b83b3f2f9200052fe34fe8b82a0fbabfc1a72cReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor jar package name xerces Highest Vendor pom artifactid Xerces Low Vendor manifest: org/apache/xerces/impl/Version Implementation-Vendor Apache Software Foundation Medium Vendor jar package name apache Highest Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor pom groupid Xerces Highest Vendor file name Xerces High Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor manifest: org.apache.xerces.xni/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Product jar package name impl Highest Product jar package name parsers Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product jar package name xni Highest Product jar package name dom Highest Product jar package name version Highest Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product jar package name w3c Highest Product jar package name xml Highest Product manifest: org.apache.xerces.xni/ Specification-Title Xerces Native Interface Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product pom artifactid Xerces Highest Product jar package name xerces Highest Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product manifest: org.apache.xerces.xni/ Implementation-Title org.apache.xerces.xni Medium Product jar package name apache Highest Product pom groupid Xerces Highest Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product file name Xerces High Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium Product manifest: org/apache/xerces/impl/Version Implementation-Title org.apache.xerces.impl.Version Medium Version file version 2.5.0 High Version manifest: org/apache/xerces/impl/Version Implementation-Version 2.5.0 Medium Version pom version 2.5.0 Highest
aopalliance-repackaged-2.5.0-b32.jarDescription:
Dependency Injection Kernel License:
https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/external/aopalliance-repackaged/2.5.0-b32/aopalliance-repackaged-2.5.0-b32.jar
MD5: 99809f55109881865ce8b47f03522fb6
SHA1: 6af37c3f8ec6f9e9653ec837eb508da28ce443cd
SHA256: 32a44ed0258c00bb8f0acf7e4dbf000a377bd48702465f6195f878a6dc2024d6
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.glassfish.hk2.external Highest Vendor file name aopalliance-repackaged High Vendor pom parent-artifactid external Low Vendor pom groupid glassfish.hk2.external Highest Vendor pom parent-groupid org.glassfish.hk2 Medium Vendor Manifest bundle-symbolicname org.glassfish.hk2.external.aopalliance-repackaged Medium Vendor pom name aopalliance version ${aopalliance.version} repackaged as a module High Vendor jar package name aopalliance Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor pom artifactid aopalliance-repackaged Low Product file name aopalliance-repackaged High Product pom artifactid aopalliance-repackaged Highest Product pom groupid glassfish.hk2.external Highest Product pom parent-artifactid external Medium Product pom parent-groupid org.glassfish.hk2 Medium Product Manifest bundle-symbolicname org.glassfish.hk2.external.aopalliance-repackaged Medium Product pom name aopalliance version ${aopalliance.version} repackaged as a module High Product Manifest Bundle-Name aopalliance version 1.0 repackaged as a module Medium Product jar package name aopalliance Highest Product Manifest bundle-docurl http://www.oracle.com Low Version pom version 2.5.0-b32 Highest
commons-beanutils-1.9.4.jarDescription:
Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar
MD5: 07dc532ee316fe1f2f0323e9bd2f8df4
SHA1: d52b9abcd97f38c81342bb7e7ae1eee9b73cba51
SHA256: 7d938c81789028045c08c065e94be75fc280527620d5bd62b519d5838532368a
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom url https://commons.apache.org/proper/commons-beanutils/ Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid commons-beanutils Low Vendor pom name Apache Commons BeanUtils High Vendor jar package name commons Highest Vendor Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Vendor jar package name apache Highest Vendor pom groupid commons-beanutils Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor file name commons-beanutils High Vendor jar package name beanutils Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom url https://commons.apache.org/proper/commons-beanutils/ Medium Product pom name Apache Commons BeanUtils High Product jar package name commons Highest Product Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Apache Commons BeanUtils Medium Product pom artifactid commons-beanutils Highest Product Manifest Implementation-Title Apache Commons BeanUtils High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Product jar package name apache Highest Product Manifest Bundle-Name Apache Commons BeanUtils Medium Product pom groupid commons-beanutils Highest Product file name commons-beanutils High Product jar package name beanutils Highest Version file version 1.9.4 High Version Manifest Bundle-Version 1.9.4 High Version pom parent-version 1.9.4 Low Version Manifest Implementation-Version 1.9.4 High Version pom version 1.9.4 Highest
commons-cli-1.4.jarDescription:
Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-cli/commons-cli/1.4/commons-cli-1.4.jar
MD5: c966d7e03507c834d5b09b848560174e
SHA1: c51c00206bb913cd8612b24abd9fa98ae89719b1
SHA256: fd3c7c9545a9cdb2051d1f9155c4f76b1e4ac5a57304404a6eedb578ffba7328
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://commons.apache.org/proper/commons-cli/ Highest Vendor jar package name cli Highest Vendor Manifest implementation-build tags/cli-1.4-RC1@r1786159; 2017-03-09 13:01:35+0000 Low Vendor jar package name commons Highest Vendor pom artifactid commons-cli Low Vendor pom name Apache Commons CLI High Vendor Manifest implementation-url http://commons.apache.org/proper/commons-cli/ Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor jar package name apache Highest Vendor file name commons-cli High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-cli/ Low Vendor pom groupid commons-cli Highest Vendor Manifest bundle-symbolicname org.apache.commons.cli Medium Product Manifest Implementation-Title Apache Commons CLI High Product jar package name cli Highest Product Manifest specification-title Apache Commons CLI Medium Product Manifest implementation-build tags/cli-1.4-RC1@r1786159; 2017-03-09 13:01:35+0000 Low Product jar package name commons Highest Product pom artifactid commons-cli Highest Product pom name Apache Commons CLI High Product Manifest Bundle-Name Apache Commons CLI Medium Product pom parent-artifactid commons-parent Medium Product Manifest implementation-url http://commons.apache.org/proper/commons-cli/ Low Product pom url http://commons.apache.org/proper/commons-cli/ Medium Product pom parent-groupid org.apache.commons Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product jar package name apache Highest Product file name commons-cli High Product Manifest bundle-docurl http://commons.apache.org/proper/commons-cli/ Low Product Manifest bundle-symbolicname org.apache.commons.cli Medium Product pom groupid commons-cli Highest Version Manifest Implementation-Version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest Version file version 1.4 High
commons-codec-1.15.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-codec/commons-codec/1.15/commons-codec-1.15.jar
MD5: 303baf002ce6d382198090aedd9d79a2
SHA1: 49d94806b6e3dc933dacbd8acb0fdbab8ebd1e5d
SHA256: b3e9f6d63a790109bf0d056611fbed1cf69055826defeb9894a71369d246ed63
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest build-jdk-spec 1.8 Low Vendor pom groupid commons-codec Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor jar package name commons Highest Vendor file name commons-codec High Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Vendor jar package name codec Highest Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor pom name Apache Commons Codec High Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name apache Highest Vendor pom artifactid commons-codec Low Vendor jar package name encoder Highest Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest build-jdk-spec 1.8 Low Product pom url https://commons.apache.org/proper/commons-codec/ Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest automatic-module-name org.apache.commons.codec Medium Product pom groupid commons-codec Highest Product jar package name commons Highest Product file name commons-codec High Product Manifest specification-title Apache Commons Codec Medium Product pom parent-artifactid commons-parent Medium Product jar package name codec Highest Product pom parent-groupid org.apache.commons Medium Product pom name Apache Commons Codec High Product pom artifactid commons-codec Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name apache Highest Product jar package name encoder Highest Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Version pom version 1.15 Highest Version file version 1.15 High Version Manifest Implementation-Version 1.15 High Version pom parent-version 1.15 Low
commons-collections-3.2.2.jarDescription:
Types that extend and augment the Java Collections Framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256: eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium Vendor jar package name commons Highest Vendor pom groupid commons-collections Highest Vendor pom artifactid commons-collections Low Vendor jar package name collections Highest Vendor pom name Apache Commons Collections High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-url http://commons.apache.org/collections/ Low Vendor file name commons-collections High Vendor jar package name apache Highest Vendor pom url http://commons.apache.org/collections/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Product pom artifactid commons-collections Highest Product Manifest bundle-docurl http://commons.apache.org/collections/ Low Product pom url http://commons.apache.org/collections/ Medium Product Manifest bundle-symbolicname org.apache.commons.collections Medium Product jar package name commons Highest Product pom groupid commons-collections Highest Product Manifest Bundle-Name Apache Commons Collections Medium Product pom parent-artifactid commons-parent Medium Product jar package name collections Highest Product pom name Apache Commons Collections High Product Manifest Implementation-Title Apache Commons Collections High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Product Manifest specification-title Apache Commons Collections Medium Product Manifest implementation-url http://commons.apache.org/collections/ Low Product file name commons-collections High Product jar package name apache Highest Version file version 3.2.2 High Version pom version 3.2.2 Highest Version Manifest Implementation-Version 3.2.2 High Version Manifest Bundle-Version 3.2.2 High Version pom parent-version 3.2.2 Low
commons-compress-1.20.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/apache/commons/commons-compress/1.20/commons-compress-1.20.jar
MD5: 3f7237fb56029591b5bdd2698c196220
SHA1: b8df472b31e1f17c232d2ad78ceb1c84e00c641b
SHA256: 0aeb625c948c697ea7b205156e112363b59ed5e2551212cd4e460bdb72c7c06e
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Vendor jar package name commons Highest Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Vendor pom parent-artifactid commons-parent Low Vendor pom groupid apache.commons Highest Vendor jar package name compress Highest Vendor Manifest implementation-build UNKNOWN@rf7503adfbad8b44eb079d564f2784aeaa034647c; 2020-02-05 05:01:35+0000 Low Vendor pom groupid org.apache.commons Highest Vendor pom artifactid commons-compress Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor jar package name apache Highest Vendor pom name Apache Commons Compress High Vendor file name commons-compress High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product pom artifactid commons-compress Highest Product Manifest specification-title Apache Commons Compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest automatic-module-name org.apache.commons.compress Medium Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Product Manifest Implementation-Title Apache Commons Compress High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Product pom groupid apache.commons Highest Product jar package name compress Highest Product Manifest implementation-build UNKNOWN@rf7503adfbad8b44eb079d564f2784aeaa034647c; 2020-02-05 05:01:35+0000 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product jar package name apache Highest Product pom name Apache Commons Compress High Product file name commons-compress High Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Version file version 1.20 High Version pom parent-version 1.20 Low Version pom version 1.20 Highest Version Manifest Implementation-Version 1.20 High
commons-daemon-1.2.4.jarDescription:
Apache Commons Daemon software is a set of utilities and Java support
classes for running Java applications as server processes. These are
commonly known as 'daemon' processes in Unix terminology (hence the
name). On Windows they are called 'services'.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-daemon/commons-daemon/1.2.4/commons-daemon-1.2.4.jar
MD5: 3b09311652913abfa26325b07ad35b14
SHA1: d60046797e74222fc6df647ffb9ab32946615264
SHA256: e9ca86791491454eb065475ded6f1d9669a6a015fd0f179ae0a92b20b8e0a71c
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name support Highest Vendor Manifest implementation-build master@r0373c020f233236ca7acf4fa4ceef31e27b7cb70; 2021-01-18 16:50:29+0000 Low Vendor pom name Apache Commons Daemon High Vendor Manifest bundle-symbolicname org.apache.commons.commons-daemon Medium Vendor jar package name commons Highest Vendor pom groupid commons-daemon Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-daemon/ Low Vendor file name commons-daemon High Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid commons-daemon Low Vendor pom url https://commons.apache.org/proper/commons-daemon/ Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name daemon Highest Product Manifest Bundle-Name Apache Commons Daemon Medium Product Manifest build-jdk-spec 1.8 Low Product jar package name support Highest Product Manifest implementation-build master@r0373c020f233236ca7acf4fa4ceef31e27b7cb70; 2021-01-18 16:50:29+0000 Low Product pom name Apache Commons Daemon High Product Manifest bundle-symbolicname org.apache.commons.commons-daemon Medium Product jar package name commons Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-daemon/ Low Product pom groupid commons-daemon Highest Product pom parent-artifactid commons-parent Medium Product file name commons-daemon High Product Manifest Implementation-Title Apache Commons Daemon High Product pom parent-groupid org.apache.commons Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid commons-daemon Highest Product jar package name apache Highest Product pom url https://commons.apache.org/proper/commons-daemon/ Medium Product Manifest specification-title Apache Commons Daemon Medium Product jar package name daemon Highest Version pom version 1.2.4 Highest Version Manifest Implementation-Version 1.2.4 High Version Manifest Bundle-Version 1.2.4 High Version pom parent-version 1.2.4 Low Version file version 1.2.4 High
commons-dbcp-1.4.jarDescription:
Commons Database Connection Pooling License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
SHA256: a6e2d83551d0e5b59aa942359f3010d35e79365e6552ad3dbaa6776e4851e4f6
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://commons.apache.org/dbcp/ Highest Vendor Manifest bundle-docurl http://commons.apache.org/dbcp/ Low Vendor jar package name commons Highest Vendor jar package name dbcp Highest Vendor file name commons-dbcp High Vendor Manifest bundle-symbolicname org.apache.commons.dbcp Medium Vendor pom parent-groupid org.apache.commons Medium Vendor pom groupid commons-dbcp Highest Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-dbcp Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom name Commons DBCP High Product Manifest bundle-docurl http://commons.apache.org/dbcp/ Low Product pom url http://commons.apache.org/dbcp/ Medium Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product jar package name dbcp Highest Product file name commons-dbcp High Product Manifest bundle-symbolicname org.apache.commons.dbcp Medium Product Manifest Implementation-Title Commons DBCP High Product pom parent-groupid org.apache.commons Medium Product pom groupid commons-dbcp Highest Product Manifest specification-title Commons DBCP Medium Product jar package name apache Highest Product Manifest Bundle-Name Commons DBCP Medium Product pom artifactid commons-dbcp Highest Product pom name Commons DBCP High Version Manifest Implementation-Version 1.4 High Version Manifest Bundle-Version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest Version file version 1.4 High
commons-exec-1.3.jarDescription:
Apache Commons Exec is a library to reliably execute external processes from within the JVM. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/apache/commons/commons-exec/1.3/commons-exec-1.3.jar
MD5: 8bb8fa2edfd60d5c7ed6bf9923d14aa8
SHA1: 8dfb9facd0830a27b1b5f29f84593f0aeee7773b
SHA256: cb49812dc1bfb0ea4f20f398bcae1a88c6406e213e67f7524fb10d4f8ad9347b
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name exec Highest Vendor jar package name commons Highest Vendor pom artifactid commons-exec Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-exec/ Low Vendor pom name Apache Commons Exec High Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor pom groupid apache.commons Highest Vendor pom url http://commons.apache.org/proper/commons-exec/ Highest Vendor file name commons-exec High Vendor Manifest bundle-symbolicname org.apache.commons.exec Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor pom groupid org.apache.commons Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest implementation-build trunk@r1636211; 2014-11-02 23:51:55+0000 Low Product jar package name exec Highest Product pom artifactid commons-exec Highest Product jar package name commons Highest Product Manifest Bundle-Name Apache Commons Exec Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-exec/ Low Product pom parent-artifactid commons-parent Medium Product pom name Apache Commons Exec High Product Manifest Implementation-Title Apache Commons Exec High Product pom parent-groupid org.apache.commons Medium Product pom groupid apache.commons Highest Product file name commons-exec High Product Manifest bundle-symbolicname org.apache.commons.exec Medium Product Manifest specification-title Apache Commons Exec Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product jar package name apache Highest Product Manifest implementation-build trunk@r1636211; 2014-11-02 23:51:55+0000 Low Product pom url http://commons.apache.org/proper/commons-exec/ Medium Version Manifest Implementation-Version 1.3 High Version pom parent-version 1.3 Low Version file version 1.3 High Version pom version 1.3 Highest
commons-io-2.6.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar
MD5: 467c2a1f64319c99b5faf03fc78572af
SHA1: 815893df5f31da2ece4040fe0a12fd44b577afaf
SHA256: f877d304660ac2a142f3865badfc971dec7ed73c747c7f8d5d2f5139ca736513
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid commons-io Highest Vendor file name commons-io High Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor jar package name commons Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Vendor pom artifactid commons-io Low Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor jar package name io Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name apache Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest Implementation-Vendor-Id commons-io Medium Vendor pom name Apache Commons IO High Product Manifest Bundle-Name Apache Commons IO Medium Product file name commons-io High Product pom groupid commons-io Highest Product pom url http://commons.apache.org/proper/commons-io/ Medium Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest specification-title Apache Commons IO Medium Product jar package name commons Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product Manifest Implementation-Title Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-io Highest Product pom parent-groupid org.apache.commons Medium Product jar package name io Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name apache Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Product Manifest bundle-symbolicname org.apache.commons.io Medium Product pom name Apache Commons IO High Version pom version 2.6 Highest Version file version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom parent-version 2.6 Low
commons-logging-1.2.jarDescription:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256: daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor pom name Apache Commons Logging High Vendor pom parent-groupid org.apache.commons Medium Vendor file name commons-logging High Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-logging Low Vendor pom groupid commons-logging Highest Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Vendor jar package name apache Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Product pom artifactid commons-logging Highest Product Manifest Bundle-Name Apache Commons Logging Medium Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product jar package name commons Highest Product jar package name logging Highest Product pom name Apache Commons Logging High Product pom url http://commons.apache.org/proper/commons-logging/ Medium Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Apache Commons Logging Medium Product pom parent-groupid org.apache.commons Medium Product file name commons-logging High Product pom groupid commons-logging Highest Product Manifest Implementation-Title Apache Commons Logging High Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Product jar package name apache Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Version pom parent-version 1.2 Low Version Manifest Implementation-Version 1.2 High Version file version 1.2 High Version pom version 1.2 Highest
commons-net-3.6-ftp.jarFile Path: /home/frederic/.m2/repository/commons-net/commons-net/3.6/commons-net-3.6-ftp.jarMD5: 562c152e7dcc52fc1c943bbce6410f86SHA1: 7d6800824dfed812250c64d9a8c9d4f4ddd5299bSHA256: 0c19e70f0e3fd5bf10bcecebf4ff22969dfa713a4ea2ee313df8673dc9761a74Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name commons-net High Vendor jar package name commons Low Vendor jar package name commons Highest Vendor jar package name net Low Vendor Manifest implementation-build tags/NET_3_6_RC1@r1782607; 2017-02-11 15:16:26+0000 Low Vendor jar package name net Highest Vendor pom groupid commons-net Highest Vendor jar package name apache Highest Vendor Manifest extension-name org.apache.commons.net Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name apache Low Product file name commons-net High Product jar package name commons Low Product jar package name commons Highest Product jar package name net Low Product Manifest implementation-build tags/NET_3_6_RC1@r1782607; 2017-02-11 15:16:26+0000 Low Product Manifest specification-title Apache Commons Net Medium Product jar package name net Highest Product jar package name ftp Low Product pom artifactid commons-net Highest Product Manifest Implementation-Title Apache Commons Net High Product jar package name apache Highest Product Manifest extension-name org.apache.commons.net Medium Version Manifest Implementation-Version 3.6 High Version file version 3.6 High Version pom version 3.6 Highest
commons-pool-1.6.jarDescription:
Commons Object Pooling Library License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
SHA256: 46c42b4a38dc6b2db53a9ee5c92c63db103665d56694e2cfce2c95d51a6860cc
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name pool Highest Vendor pom url http://commons.apache.org/pool/ Highest Vendor pom name Commons Pool High Vendor jar package name commons Highest Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-pool Low Vendor pom groupid commons-pool Highest Vendor file name commons-pool High Vendor jar package name apache Highest Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low Product Manifest Bundle-Name Commons Pool Medium Product jar package name pool Highest Product pom artifactid commons-pool Highest Product pom name Commons Pool High Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Commons Pool Medium Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Product pom url http://commons.apache.org/pool/ Medium Product pom parent-groupid org.apache.commons Medium Product pom groupid commons-pool Highest Product file name commons-pool High Product jar package name apache Highest Product Manifest bundle-symbolicname org.apache.commons.pool Medium Product Manifest Implementation-Title Commons Pool High Product Manifest bundle-docurl http://commons.apache.org/pool/ Low Version pom parent-version 1.6 Low Version pom version 1.6 Highest Version Manifest Implementation-Version 1.6 High Version file version 1.6 High
dom4j-2.0.3.jarDescription:
flexible XML framework for Java License:
BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE File Path: /home/frederic/.m2/repository/org/dom4j/dom4j/2.0.3/dom4j-2.0.3.jar
MD5: e52772ce926518c4b58ce7084cb365f1
SHA1: 486bf7f9c368f621e616b9a3532253f23665a104
SHA256: b9ee0981b983ff71605c63cae5c12e0e5facb030bc1c1cd586447e28afc2876e
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.dom4j Highest Vendor pom artifactid dom4j Low Vendor file name dom4j High Vendor pom url http://dom4j.github.io/ Highest Vendor pom groupid dom4j Highest Vendor pom name dom4j High Vendor jar package name dom4j Highest Vendor jar package name dom4j Low Product pom artifactid dom4j Highest Product file name dom4j High Product pom url http://dom4j.github.io/ Medium Product pom groupid dom4j Highest Product pom name dom4j High Product jar package name dom4j Highest Version pom version 2.0.3 Highest Version file version 2.0.3 High
ftp4j-1.7.2.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/it/sauronsoftware/ftp4j/1.7.2/ftp4j-1.7.2.jarMD5: 9b5971848287cbe7b44cbd65030bb8a6SHA1: abd6a2ba75b142926052c4538611efda49e0b0e2SHA256: af8093a956cc5fc7289e72607b7ece2325db292b1ab7cf728dc876d3ad69061dReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid it.sauronsoftware Highest Vendor jar package name ftp4j Low Vendor jar package name it Highest Vendor jar package name sauronsoftware Highest Vendor pom artifactid ftp4j Low Vendor jar package name it Low Vendor jar package name sauronsoftware Low Vendor jar package name ftp4j Highest Vendor file name ftp4j High Product pom groupid it.sauronsoftware Highest Product jar package name ftp4j Low Product pom artifactid ftp4j Highest Product jar package name it Highest Product jar package name sauronsoftware Highest Product jar package name sauronsoftware Low Product jar package name ftp4j Highest Product file name ftp4j High Version file version 1.7.2 High Version pom version 1.7.2 Highest
guava-20.0.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/google/guava/guava/20.0/guava-20.0.jar
MD5: f32a8a2524620dbecc9f6bf6a20c293f
SHA1: 89507701249388e1ed5ddcf8c41f4ce1be7831ef
SHA256: 36a666e3b71ae7f0f0dca23654b67e086e6c93d192f60ba5dfd5519db6c288c8
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name guava High Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom parent-groupid com.google.guava Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid guava Low Vendor pom groupid google.guava Highest Vendor pom parent-artifactid guava-parent Low Vendor jar package name google Highest Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor pom name Guava: Google Core Libraries for Java High Vendor pom groupid com.google.guava Highest Product file name guava High Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom groupid google.guava Highest Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product jar package name google Highest Product Manifest bundle-docurl https://github.com/google/guava/ Low Product pom parent-artifactid guava-parent Medium Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Version pom version 20.0 Highest Version file version 20.0 High
Published Vulnerabilities CVE-2018-10237 suppress
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MLIST - [activemq-gitbox] 20190530 [GitHub] [activemq-artemis] brusdev opened a new pull request #2687: ARTEMIS-2359 Upgrade to Guava 24.1 MLIST - [activemq-issues] 20190516 [jira] [Created] (AMQ-7208) Security Issue related to Guava 18.0 MLIST - [activemq-issues] 20190820 [jira] [Created] (AMQ-7279) Security Vulnerabilities in Libraries - jackson-databind-2.9.8.jar, tomcat-servlet-api-8.0.53.jar, tomcat-websocket-api-8.0.53.jar, zookeeper-3.4.6.jar, guava-18.0.jar, jetty-all-9.2.26.v20180806.jar, scala-library-2.11.0.jar MLIST - [cassandra-commits] 20190612 [jira] [Assigned] (CASSANDRA-14760) CVE-2018-10237 Security vulnerability in 3.11.3 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] davidkarlsen opened a new pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200211 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] andrei-ivanov commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [drill-dev] 20191017 Dependencies used by Drill contain known vulnerabilities MLIST - [drill-dev] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [drill-issues] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [flink-dev] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [flink-dev] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200814 [jira] [Commented] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20210212 [jira] [Closed] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-user] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [hadoop-common-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [hadoop-common-dev] 20200623 Update guava to 27.0-jre in hadoop branch-2.10 MLIST - [hadoop-hdfs-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [kafka-users] 20200413 CVEs for the dependency software guava and rocksdbjni of Kafka MLIST - [lucene-issues] 20201022 [jira] [Created] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Resolved] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Updated] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [maven-issues] 20210122 [GitHub] [maven-indexer] akurtakov opened a new pull request #75: Remove guava dependency from indexer-core MLIST - [pulsar-commits] 20190416 [GitHub] [pulsar] one70six opened a new issue #4057: Security Vulnerabilities - Black Duck Scan - Pulsar v.2.3.1 MLIST - [syncope-dev] 20200423 Re: Time to cut 2.1.6 / 2.0.15? N/A - N/A OSSINDEX - [CVE-2018-10237] Deserialization of Untrusted Data REDHAT - RHSA-2018:2423 REDHAT - RHSA-2018:2424 REDHAT - RHSA-2018:2425 REDHAT - RHSA-2018:2428 REDHAT - RHSA-2018:2598 REDHAT - RHSA-2018:2643 REDHAT - RHSA-2018:2740 REDHAT - RHSA-2018:2741 REDHAT - RHSA-2018:2742 REDHAT - RHSA-2018:2743 REDHAT - RHSA-2018:2927 REDHAT - RHSA-2019:2858 REDHAT - RHSA-2019:3149 SECTRACK - 1041707 Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
h2-1.4.191.jarDescription:
H2 Database Engine License:
MPL 2.0, and EPL 1.0: http://h2database.com/html/license.html File Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar
MD5: dda3c5e5615f0e29a9bc6b14d20fb0c2
SHA1: dec3540178ea889b2871b0ed56db14bbec9cfdfc
SHA256: e21ea665b74ec0115344b5afda5ec70ea27b528c3f103524e74c9854b1c4a284
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://www.h2database.com Low Vendor pom groupid h2database Highest Vendor pom artifactid h2 Low Vendor Manifest bundle-category jdbc Low Vendor jar package name database Highest Vendor pom name H2 Database Engine High Vendor file name h2 High Vendor jar package name h2 Highest Vendor Manifest bundle-symbolicname org.h2 Medium Vendor jar package name engine Highest Vendor pom groupid com.h2database Highest Vendor pom url http://www.h2database.com Highest Product Manifest implementation-url http://www.h2database.com Low Product pom groupid h2database Highest Product Manifest Implementation-Title H2 Database Engine High Product Manifest bundle-category jdbc Low Product pom url http://www.h2database.com Medium Product jar package name database Highest Product jar package name jdbc Highest Product pom name H2 Database Engine High Product file name h2 High Product Manifest Bundle-Name H2 Database Engine Medium Product jar package name h2 Highest Product pom artifactid h2 Highest Product Manifest bundle-symbolicname org.h2 Medium Product jar package name engine Highest Version pom version 1.4.191 Highest Version Manifest Bundle-Version 1.4.191 High Version file version 1.4.191 High Version Manifest Implementation-Version 1.4.191 High
h2-1.4.191.jar: data.zip: table.jsFile Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar/org/h2/util/data.zip/org/h2/server/web/res/table.jsMD5: a914a66de53dcdeb39684f1ce8ce8527SHA1: c41ef5fb193ac25622f4e129470339aec24d731aSHA256: 8c5b079b38e94718bb58a71b0e310bad6c1004670a19c1bc0f63b32fdd81134aReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence
h2-1.4.191.jar: data.zip: tree.jsFile Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.jsMD5: 495277155635a72b0c69f987d938b6e1SHA1: 446cad47e33a62baf330ee5200646b5ccb9c0df9SHA256: 14c797bd700570c38e8af1aa50ecea205a385be466ec9431e46dbe586ce7a61cReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence
hk2-api-2.5.0-b32.jarDescription:
${project.name} License:
https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/hk2-api/2.5.0-b32/hk2-api-2.5.0-b32.jar
MD5: 93322931c4ec277c5190c7cddf7ad155
SHA1: 6a576c9653832ce610b80a2f389374ef19d96171
SHA256: b3fe4f295ab8e74ea9d641717dc55e5768f1e5db3709e84235346a4d6bcde5c2
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name glassfish Highest Vendor pom groupid glassfish.hk2 Highest Vendor pom parent-artifactid hk2-parent Low Vendor pom name HK2 API module High Vendor pom groupid org.glassfish.hk2 Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor file name hk2-api High Vendor jar package name api Highest Vendor Manifest bundle-symbolicname org.glassfish.hk2.api Medium Vendor pom parent-groupid org.glassfish.hk2 Medium Vendor jar package name hk2 Highest Vendor pom artifactid hk2-api Low Product Manifest Bundle-Name HK2 API module Medium Product pom artifactid hk2-api Highest Product jar package name glassfish Highest Product pom groupid glassfish.hk2 Highest Product pom name HK2 API module High Product pom parent-artifactid hk2-parent Medium Product Manifest bundle-docurl http://www.oracle.com Low Product file name hk2-api High Product jar package name api Highest Product Manifest bundle-symbolicname org.glassfish.hk2.api Medium Product pom parent-groupid org.glassfish.hk2 Medium Product jar package name hk2 Highest Version pom version 2.5.0-b32 Highest
hk2-locator-2.5.0-b32.jarDescription:
${project.name} License:
https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/hk2-locator/2.5.0-b32/hk2-locator-2.5.0-b32.jar
MD5: 5baf0f144cf8552a9fe476b096fc18a7
SHA1: 195474f8ad0a8d130e9ea949a771bcf1215fc33b
SHA256: 27cacf80e8c088cc50f73b56344b779bdb7418e590a037659ab66b2b0cd9c492
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name hk2-locator High Vendor Manifest bundle-symbolicname org.glassfish.hk2.locator Medium Vendor pom groupid glassfish.hk2 Highest Vendor pom parent-groupid org.glassfish.hk2 Medium Vendor pom artifactid hk2-locator Low Vendor pom parent-artifactid hk2-parent Low Vendor pom groupid org.glassfish.hk2 Highest Vendor pom name ServiceLocator Default Implementation High Vendor jar package name hk2 Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Product pom artifactid hk2-locator Highest Product file name hk2-locator High Product Manifest bundle-symbolicname org.glassfish.hk2.locator Medium Product pom groupid glassfish.hk2 Highest Product pom parent-groupid org.glassfish.hk2 Medium Product pom name ServiceLocator Default Implementation High Product Manifest Bundle-Name ServiceLocator Default Implementation Medium Product pom parent-artifactid hk2-parent Medium Product jar package name hk2 Highest Product Manifest bundle-docurl http://www.oracle.com Low Version pom version 2.5.0-b32 Highest
hk2-utils-2.5.0-b32.jarDescription:
${project.name} License:
https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/hk2-utils/2.5.0-b32/hk2-utils-2.5.0-b32.jar
MD5: acc873aece4f8e89814ac0300b549e3e
SHA1: 5108a926988c4ceda7f1e681dddfe3101454a002
SHA256: 3912c470e621eb3e469c111f4c9a4dee486e2ce9db09a65b7609e006b6c3d38e
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name utilities Highest Vendor jar package name glassfish Highest Vendor pom groupid glassfish.hk2 Highest Vendor Manifest service foo Low Vendor pom parent-artifactid hk2-parent Low Vendor pom groupid org.glassfish.hk2 Highest Vendor Manifest originally-created-by Apache Maven Low Vendor file name hk2-utils High Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor pom parent-groupid org.glassfish.hk2 Medium Vendor Manifest bundle-symbolicname org.glassfish.hk2.utils Medium Vendor pom artifactid hk2-utils Low Vendor jar package name hk2 Highest Vendor pom name HK2 Implementation Utilities High Product jar package name utilities Highest Product jar package name glassfish Highest Product pom groupid glassfish.hk2 Highest Product Manifest service foo Low Product Manifest originally-created-by Apache Maven Low Product pom parent-artifactid hk2-parent Medium Product file name hk2-utils High Product Manifest bundle-docurl http://www.oracle.com Low Product pom parent-groupid org.glassfish.hk2 Medium Product Manifest bundle-symbolicname org.glassfish.hk2.utils Medium Product Manifest Bundle-Name HK2 Implementation Utilities Medium Product jar package name hk2 Highest Product pom artifactid hk2-utils Highest Product pom name HK2 Implementation Utilities High Version pom version 2.5.0-b32 Highest
hk2-utils-2.5.0-b32.jar (shaded: org.jvnet:tiger-types:1.4)File Path: /home/frederic/.m2/repository/org/glassfish/hk2/hk2-utils/2.5.0-b32/hk2-utils-2.5.0-b32.jar/META-INF/maven/org.jvnet/tiger-types/pom.xmlMD5: 51329dba505e7cc4a9bc2719cf195be0SHA1: 5855a7ee03b816073c2b448bce93319bd71f7029SHA256: 58794aca99cadb3aab687b56fd6d84871956590323dd0ea5d611db759e78c6b9Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid net.java Medium Vendor pom name Type arithmetic library for Java5 High Vendor pom parent-artifactid jvnet-parent Low Vendor pom groupid jvnet Highest Vendor pom artifactid tiger-types Low Product pom parent-groupid net.java Medium Product pom name Type arithmetic library for Java5 High Product pom parent-artifactid jvnet-parent Medium Product pom groupid jvnet Highest Product pom artifactid tiger-types Highest Version pom parent-version 1.4 Low Version pom version 1.4 Highest
httpclient-4.5.13.jarDescription:
Apache HttpComponents Client
File Path: /home/frederic/.m2/repository/org/apache/httpcomponents/httpclient/4.5.13/httpclient-4.5.13.jarMD5: 40d6b9075fbd28fa10292a45a0db9457SHA1: e5f6cae5ca7ecaac1ec2827a9e2d65ae2869cadaSHA256: 6fe9026a566c6a5001608cf3fc32196641f6c1e5e1986d1037ccdbd5f31ef743Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid httpcomponents-client Low Vendor jar package name client Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor pom name Apache HttpClient High Vendor file name httpclient High Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor jar package name httpclient Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor pom artifactid httpclient Low Vendor jar package name apache Highest Vendor pom url http://hc.apache.org/httpcomponents-client Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Product Manifest specification-title Apache HttpClient Medium Product jar package name client Highest Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Product pom name Apache HttpClient High Product file name httpclient High Product pom groupid apache.httpcomponents Highest Product pom parent-groupid org.apache.httpcomponents Medium Product jar package name httpclient Highest Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Product jar package name apache Highest Product Manifest Implementation-Title Apache HttpClient High Product jar package name http Highest Product pom artifactid httpclient Highest Version file version 4.5.13 High Version pom version 4.5.13 Highest Version Manifest Implementation-Version 4.5.13 High
httpcore-4.4.14.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /home/frederic/.m2/repository/org/apache/httpcomponents/httpcore/4.4.14/httpcore-4.4.14.jarMD5: 2b3991eda121042765a5ee299556c200SHA1: 9dd1a631c082d92ecd4bd8fd4cf55026c720a8c1SHA256: f956209e450cb1d0c51776dfbd23e53e9dd8db9a1298ed62b70bf0944ba63b28Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid httpcomponents-core Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Apache HttpCore High Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor file name httpcore High Vendor pom artifactid httpcore Low Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-11-26 19:07:01+0000 Low Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom groupid org.apache.httpcomponents Highest Vendor jar package name apache Highest Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Product pom name Apache HttpCore High Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product pom artifactid httpcore Highest Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product file name httpcore High Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-11-26 19:07:01+0000 Low Product pom groupid apache.httpcomponents Highest Product pom parent-groupid org.apache.httpcomponents Medium Product jar package name apache Highest Product jar package name http Highest Product pom parent-artifactid httpcomponents-core Medium Version file version 4.4.14 High Version Manifest Implementation-Version 4.4.14 High Version pom version 4.4.14 Highest
jackson-core-2.7.9.jarDescription:
Core Jackson abstractions, basic JSON streaming API implementation License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.7.9/jackson-core-2.7.9.jar
MD5: f5d0dfe03814113d792e75e885699640
SHA1: 09b530cec4fd2eb841ab8e79f19fc7cf0ec487b2
SHA256: bd90721420bb899a974ed09a107fef42ca8cc7c8e055762f6c81576132e5bbc5
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest implementation-build-date 2017-02-04 19:18:13+0000 Low Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor pom artifactid jackson-core Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom groupid fasterxml.jackson.core Highest Vendor pom url FasterXML/jackson-core Highest Vendor pom name Jackson-core High Vendor jar package name json Highest Vendor jar package name fasterxml Highest Vendor jar package name core Highest Vendor pom parent-artifactid jackson-parent Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest specification-vendor FasterXML Low Product file name jackson-core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Implementation-Title Jackson-core High Product Manifest implementation-build-date 2017-02-04 19:18:13+0000 Low Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product hint analyzer product modules Highest Product jar package name version Highest Product pom groupid fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom url FasterXML/jackson-core High Product hint analyzer product java8 Highest Product jar package name json Highest Product jar package name fasterxml Highest Product Manifest Bundle-Name Jackson-core Medium Product Manifest specification-title Jackson-core Medium Product jar package name core Highest Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product pom parent-artifactid jackson-parent Medium Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product jar package name filter Highest Product pom artifactid jackson-core Highest Version pom parent-version 2.7.9 Low Version file version 2.7.9 High Version pom version 2.7.9 Highest Version Manifest Implementation-Version 2.7.9 High Version Manifest Bundle-Version 2.7.9 High
Related Dependencies jackson-annotations-2.7.9.jarFile Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.7.9/jackson-annotations-2.7.9.jar MD5: 6e9df0fc4856924a1e4a51da36f37b31 SHA1: eb356e825cb73da42f7c902a3fe0276fe32b26c8 SHA256: f9a9a3db99c35324a97b6c3bc95941a0892a9da935a02620d431f7534040bf4f pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.7.9 Published Vulnerabilities CVE-2018-1000873 suppress
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jackson-databind-2.7.9.6.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.7.9.6/jackson-databind-2.7.9.6.jar
MD5: 56c7443cccf36b6bc6eb661a4d128762
SHA1: 562ce1931544a1ae4a3d0e8523c2068fea4198fa
SHA256: 368c7a722e45d8bbbbbfad953f4999c383ecab5bf366fa85ed4115534e377a43
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor Manifest implementation-build-date 2019-07-26 05:00:34+0000 Low Vendor pom groupid fasterxml.jackson.core Highest Vendor jar package name databind Highest Vendor file name jackson-databind High Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor jar package name fasterxml Highest Vendor pom artifactid jackson-databind Low Vendor pom parent-artifactid jackson-parent Low Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor pom url http://github.com/FasterXML/jackson Highest Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest specification-vendor FasterXML Low Vendor pom name jackson-databind High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Bundle-Name jackson-databind Medium Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product pom url http://github.com/FasterXML/jackson Medium Product hint analyzer product modules Highest Product Manifest implementation-build-date 2019-07-26 05:00:34+0000 Low Product pom groupid fasterxml.jackson.core Highest Product jar package name databind Highest Product file name jackson-databind High Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product hint analyzer product java8 Highest Product Manifest Implementation-Title jackson-databind High Product jar package name fasterxml Highest Product Manifest specification-title jackson-databind Medium Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product pom parent-artifactid jackson-parent Medium Product pom artifactid jackson-databind Highest Product pom name jackson-databind High Version file version 2.7.9.6 High Version pom version 2.7.9.6 Highest Version pom parent-version 2.7.9.6 Low Version Manifest Bundle-Version 2.7.9.6 High Version Manifest Implementation-Version 2.7.9.6 High
Published Vulnerabilities CVE-2017-15095 (OSSINDEX) suppress
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2017-17485 (OSSINDEX) suppress
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2018-1000873 suppress
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-14540 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-14893 (OSSINDEX) suppress
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16335 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16942 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16943 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-17267 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-17531 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-20330 suppress
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-10672 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10673 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10968 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10969 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-11111 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11112 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11113 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11619 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11620 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14060 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14061 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14062 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14195 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-24616 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-24750 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-35490 suppress
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-35491 suppress
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-8840 suppress
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-9546 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2631 MISC - https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9546] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
CVE-2020-9547 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2634 MISC - https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 Build failed in Jenkins: PreCommit-ZOOKEEPER-github-pr-build-maven #1898 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9547] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
CVE-2020-9548 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2634 MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9548] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
jackson-dataformat-smile-2.7.9.jarDescription:
Support for reading and writing Smile ("binary JSON")
encoded data using Jackson abstractions (streaming API, data binding,
tree model)
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-smile/2.7.9/jackson-dataformat-smile-2.7.9.jar
MD5: eb20c11444c0aeb464a7302930ec18e0
SHA1: 3aef8d360e5bb6f8044964ba831f5cd53a663fe3
SHA256: 8df9cfc493a3e3c6c0d5eacf019ca06b2fae7f97eac4a7efdbab6694ba1dc643
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-dataformat-smile High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-smile Medium Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url http://github.com/FasterXML/jackson-dataformat-smile Highest Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor pom name Jackson-dataformat-Smile High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor jar package name fasterxml Highest Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson-dataformat-smile Low Vendor jar package name dataformat Highest Vendor pom parent-artifactid jackson-parent Low Vendor pom groupid fasterxml.jackson.dataformat Highest Vendor Manifest implementation-build-date 2017-02-04 21:35:17+0000 Low Vendor Manifest specification-vendor FasterXML Low Vendor jar package name smile Highest Vendor pom artifactid jackson-dataformat-smile Low Product file name jackson-dataformat-smile High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Implementation-Title Jackson-dataformat-Smile High Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-smile Medium Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product Manifest Bundle-Name Jackson-dataformat-Smile Medium Product pom name Jackson-dataformat-Smile High Product jar package name fasterxml Highest Product Manifest bundle-docurl http://github.com/FasterXML/jackson-dataformat-smile Low Product pom url http://github.com/FasterXML/jackson-dataformat-smile Medium Product jar package name dataformat Highest Product Manifest specification-title Jackson-dataformat-Smile Medium Product pom artifactid jackson-dataformat-smile Highest Product pom groupid fasterxml.jackson.dataformat Highest Product pom parent-artifactid jackson-parent Medium Product Manifest implementation-build-date 2017-02-04 21:35:17+0000 Low Product jar package name smile Highest Version pom parent-version 2.7.9 Low Version file version 2.7.9 High Version pom version 2.7.9 Highest Version Manifest Implementation-Version 2.7.9 High Version Manifest Bundle-Version 2.7.9 High
jakarta.activation-api-1.2.1.jarDescription:
JavaBeans Activation Framework API jar License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/frederic/.m2/repository/jakarta/activation/jakarta.activation-api/1.2.1/jakarta.activation-api-1.2.1.jar
MD5: 9b647398add993324d3d9e5effa6005a
SHA1: 562a587face36ec7eff2db7f2fc95425c6602bc1
SHA256: 8b0a0f52fa8b05c5431921a063ed866efaa41dadf2e3a7ee3e1961f2b0d9645b
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor pom groupid jakarta.activation Highest Vendor jar package name activation Highest Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom name JavaBeans Activation Framework API jar High Vendor Manifest automatic-module-name jakarta.activation Medium Vendor file name jakarta.activation-api High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Vendor pom artifactid jakarta.activation-api Low Product pom artifactid jakarta.activation-api Highest Product Manifest Implementation-Title jakarta.activation.jakarta.activation-api High Product Manifest specification-title jakarta.activation.jakarta.activation-api Medium Product jar package name activation Highest Product pom groupid jakarta.activation Highest Product pom name JavaBeans Activation Framework API jar High Product Manifest automatic-module-name jakarta.activation Medium Product file name jakarta.activation-api High Product Manifest extension-name jakarta.activation Medium Product Manifest Bundle-Name JavaBeans Activation Framework API jar Medium Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest bundle-symbolicname jakarta.activation-api Medium Product pom parent-groupid com.sun.activation Medium Product pom parent-artifactid all Medium Version file version 1.2.1 High Version Manifest Implementation-Version 1.2.1 High Version Manifest Bundle-Version 1.2.1 High Version pom version 1.2.1 Highest
javassist-3.25.0-GA.jarDescription:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/ File Path: /home/frederic/.m2/repository/org/javassist/javassist/3.25.0-GA/javassist-3.25.0-GA.jar
MD5: 3a4267e01989478be188d127b7a39425
SHA1: 442dc1f9fd520130bd18da938622f4f9b2e5fba3
SHA256: 5d49abd02997134f80041645e9668e1ff97afd69d2c2c55ae9fbd40dc073f97b
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name javassist High Vendor pom name Javassist High Vendor jar package name javassist Highest Vendor pom groupid org.javassist Highest Vendor pom organization name Shigeru Chiba, www.javassist.org High Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom groupid javassist Highest Vendor pom url http://www.javassist.org/ Highest Vendor pom artifactid javassist Low Vendor Manifest bundle-symbolicname javassist Medium Vendor jar package name bytecode Highest Product pom organization name Shigeru Chiba, www.javassist.org Low Product Manifest specification-title Javassist Medium Product pom artifactid javassist Highest Product file name javassist High Product pom name Javassist High Product pom url http://www.javassist.org/ Medium Product Manifest Bundle-Name Javassist Medium Product jar package name javassist Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom groupid javassist Highest Product Manifest bundle-symbolicname javassist Medium Product jar package name bytecode Highest Version Manifest specification-version 3.25.0-GA High Version pom version 3.25.0-GA Highest
javax.activation-1.2.0.jarDescription:
JavaBeans Activation Framework License:
https://github.com/javaee/activation/blob/master/LICENSE.txt File Path: /home/frederic/.m2/repository/com/sun/activation/javax.activation/1.2.0/javax.activation-1.2.0.jar
MD5: be7c430df50b330cffc4848a3abedbfb
SHA1: bf744c1e2776ed1de3c55c8dac1057ec331ef744
SHA256: 993302b16cd7056f21e779cc577d175a810bb4900ef73cd8fbf2b50f928ba9ce
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest (hint) Implementation-Vendor sun High Vendor jar package name activation Highest Vendor Manifest extension-name javax.activation Medium Vendor pom groupid sun.activation Highest Vendor Manifest specification-vendor Oracle Low Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Vendor jar package name javax Highest Vendor jar package name sun Highest Vendor file name javax.activation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-symbolicname com.sun.activation.javax.activation Medium Vendor pom name JavaBeans Activation Framework High Vendor pom artifactid javax.activation Low Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Vendor Manifest automatic-module-name java.activation Medium Vendor pom groupid com.sun.activation Highest Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest (hint) specification-vendor sun Low Product pom artifactid javax.activation Highest Product Manifest Implementation-Title javax.activation High Product jar package name activation Highest Product Manifest extension-name javax.activation Medium Product pom groupid sun.activation Highest Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Product jar package name javax Highest Product jar package name sun Highest Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium Product file name javax.activation High Product Manifest Bundle-Name JavaBeans Activation Framework Medium Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest bundle-symbolicname com.sun.activation.javax.activation Medium Product pom name JavaBeans Activation Framework High Product pom parent-groupid com.sun.activation Medium Product pom parent-artifactid all Medium Product Manifest automatic-module-name java.activation Medium Version file version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version pom version 1.2.0 Highest
javax.annotation-api-1.2.jarDescription:
Common Annotations for the JavaTM Platform API License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /home/frederic/.m2/repository/javax/annotation/javax.annotation-api/1.2/javax.annotation-api-1.2.jar
MD5: 75fe320d2b3763bd6883ae1ede35e987
SHA1: 479c1e06db31c432330183f5cae684163f186146
SHA256: 5909b396ca3a2be10d0eea32c74ef78d816e1b4ead21de1d78de1f890d033e04
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name javax.annotation-api High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom organization url https://glassfish.java.net Medium Vendor pom organization name GlassFish Community High Vendor jar package name javax Highest Vendor Manifest Implementation-Vendor GlassFish Community High Vendor pom name ${extension.name} API High Vendor jar package name annotation Highest Vendor Manifest extension-name javax.annotation Medium Vendor pom parent-groupid net.java Medium Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest Vendor pom groupid javax.annotation Highest Vendor pom parent-artifactid jvnet-parent Low Vendor Manifest bundle-docurl https://glassfish.java.net Low Vendor pom artifactid javax.annotation-api Low Vendor Manifest bundle-symbolicname javax.annotation-api Medium Product file name javax.annotation-api High Product pom parent-artifactid jvnet-parent Medium Product jar package name javax Highest Product pom name ${extension.name} API High Product jar package name annotation Highest Product pom organization url https://glassfish.java.net Low Product Manifest extension-name javax.annotation Medium Product pom parent-groupid net.java Medium Product pom url http://jcp.org/en/jsr/detail?id=250 Medium Product pom artifactid javax.annotation-api Highest Product Manifest Bundle-Name javax.annotation API Medium Product pom groupid javax.annotation Highest Product pom organization name GlassFish Community Low Product Manifest bundle-docurl https://glassfish.java.net Low Product Manifest bundle-symbolicname javax.annotation-api Medium Version Manifest Bundle-Version 1.2 High Version pom parent-version 1.2 Low Version Manifest Implementation-Version 1.2 High Version file version 1.2 High Version pom version 1.2 Highest
javax.inject-2.5.0-b32.jarDescription:
Injection API (JSR 330) version ${javax.inject.version} repackaged as OSGi bundle License:
https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/external/javax.inject/2.5.0-b32/javax.inject-2.5.0-b32.jar
MD5: b7e8633eb1e5aad9f44a37a3f3bfa8f5
SHA1: b2fa50c8186a38728c35fe6a9da57ce4cc806923
SHA256: 437c92cf50a0efa6b501b8939b5b92ede7cfe4455cf06b68ec69d1b21ab921ed
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.glassfish.hk2.external Highest Vendor pom artifactid javax.inject Low Vendor pom parent-artifactid external Low Vendor jar package name inject Highest Vendor file name javax.inject High Vendor pom groupid glassfish.hk2.external Highest Vendor pom parent-groupid org.glassfish.hk2 Medium Vendor pom name javax.inject:${javax-inject.version} as OSGi bundle High Vendor jar package name javax Highest Vendor Manifest bundle-symbolicname org.glassfish.hk2.external.javax.inject Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Product pom artifactid javax.inject Highest Product jar package name inject Highest Product file name javax.inject High Product pom groupid glassfish.hk2.external Highest Product pom parent-artifactid external Medium Product pom parent-groupid org.glassfish.hk2 Medium Product Manifest Bundle-Name javax.inject:1 as OSGi bundle Medium Product pom name javax.inject:${javax-inject.version} as OSGi bundle High Product jar package name javax Highest Product Manifest bundle-symbolicname org.glassfish.hk2.external.javax.inject Medium Product Manifest bundle-docurl http://www.oracle.com Low Version pom version 2.5.0-b32 Highest
javax.ws.rs-api-2.0.1.jarDescription:
Java API for RESTful Web Services (JAX-RS) License:
CDDL 1.1: http://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/javax/ws/rs/javax.ws.rs-api/2.0.1/javax.ws.rs-api-2.0.1.jar
MD5: edcd111cf4d3ba8ac8e1f326efc37a17
SHA1: 104e9c2b5583cfcfeac0402316221648d6d8ea6b
SHA256: 38607d626f2288d8fbc1b1f8a62c369e63806d9a313ac7cbc5f9d6c94f4b466d
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor jar package name rs Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom name javax.ws.rs-api High Vendor jar package name javax Highest Vendor pom url http://jax-rs-spec.java.net Highest Vendor Manifest extension-name javax.ws.rs Medium Vendor pom parent-groupid net.java Medium Vendor pom groupid javax.ws.rs Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor file name javax.ws.rs-api High Vendor jar package name ws Highest Vendor pom parent-artifactid jvnet-parent Low Vendor pom organization url http://www.oracle.com/ Medium Vendor pom artifactid javax.ws.rs-api Low Vendor pom organization name Oracle Corporation High Vendor Manifest bundle-symbolicname javax.ws.rs-api Medium Product pom url http://jax-rs-spec.java.net Medium Product jar package name rs Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom parent-artifactid jvnet-parent Medium Product pom artifactid javax.ws.rs-api Highest Product pom name javax.ws.rs-api High Product jar package name javax Highest Product hint analyzer product web services Medium Product Manifest Bundle-Name javax.ws.rs-api Medium Product Manifest extension-name javax.ws.rs Medium Product pom parent-groupid net.java Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom groupid javax.ws.rs Highest Product pom organization name Oracle Corporation Low Product file name javax.ws.rs-api High Product jar package name ws Highest Product pom organization url http://www.oracle.com/ Low Product Manifest bundle-symbolicname javax.ws.rs-api Medium Version Manifest Implementation-Version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version file version 2.0.1 High Version pom version 2.0.1 Highest
jaxb-api-2.2.12.jarDescription:
JAXB (JSR 222) API License:
CDDL 1.1: https://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/javax/xml/bind/jaxb-api/2.2.12/jaxb-api-2.2.12.jar
MD5: 62229737e570051d2ace48592faf7d4e
SHA1: 4c83805595b15acf41d71d49e3add7c0e85baaed
SHA256: 68a621ec18485f951d09ac76f43e57eee394dbe42cb8f2a4c59c93296fa9dcc6
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom name Java Architecture for XML Binding High Vendor file name jaxb-api High Vendor Manifest implementation-build-id UNKNOWN_BRANCH-false, 2014-10-20T14:33:58+0200 Low Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor pom artifactid jaxb-api Low Vendor jar package name javax Highest Vendor jar package name xml Highest Vendor pom parent-groupid net.java Medium Vendor pom url http://jaxb.java.net/ Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest extension-name javax.xml.bind Medium Vendor jar package name bind Highest Vendor pom parent-artifactid jvnet-parent Low Vendor pom organization url http://www.oracle.com/ Medium Vendor pom organization name Oracle Corporation High Vendor pom groupid javax.xml.bind Highest Vendor jar package name jaxb Highest Product pom parent-artifactid jvnet-parent Medium Product pom name Java Architecture for XML Binding High Product file name jaxb-api High Product Manifest implementation-build-id UNKNOWN_BRANCH-false, 2014-10-20T14:33:58+0200 Low Product pom artifactid jaxb-api Highest Product Manifest bundle-symbolicname jaxb-api Medium Product jar package name javax Highest Product Manifest specification-title Java Architecture for XML Binding Medium Product jar package name xml Highest Product pom parent-groupid net.java Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest extension-name javax.xml.bind Medium Product pom organization name Oracle Corporation Low Product jar package name bind Highest Product pom url http://jaxb.java.net/ Medium Product pom organization url http://www.oracle.com/ Low Product jar package name jaxb Highest Product Manifest Bundle-Name jaxb-api Medium Product pom groupid javax.xml.bind Highest Version pom parent-version 2.2.12 Low Version pom version 2.2.12 Highest Version Manifest Bundle-Version 2.2.12 High Version file version 2.2.12 High Version Manifest specification-version 2.2.12 High
jaxb-core-2.2.11.jarDescription:
Old JAXB Core module. Contains sources required by XJC, JXC and Runtime modules with dependencies. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar
MD5: c5eca4e58a75eabe3379926803421bab
SHA1: c3f87d654f8d5943cd08592f3f758856544d279a
SHA256: b13da0c655a3d590a2a945553648c407e6347648c9f7a3f811b7b3a8a1974baa
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom groupid com.sun.xml.bind Highest Vendor pom name JAXB Core High Vendor pom parent-artifactid jaxb-bundles Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom groupid glassfish.jaxb Highest Vendor jar package name sun Highest Vendor file name jaxb-core High Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Vendor pom groupid sun.xml.bind Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor jar package name bind Highest Vendor pom parent-artifactid jaxb-parent Low Vendor pom name Old JAXB Core High Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-core Medium Vendor Manifest Implementation-Vendor Oracle High Vendor pom artifactid jaxb-core Low Product pom artifactid jaxb-core Highest Product pom name JAXB Core High Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom groupid glassfish.jaxb Highest Product jar package name sun Highest Product file name jaxb-core High Product Manifest specification-title Java Architecture for XML Binding Medium Product jar package name xml Highest Product Manifest Implementation-Title JAXB Implementation High Product Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Product pom groupid sun.xml.bind Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom parent-artifactid jaxb-bundles Medium Product pom parent-artifactid jaxb-parent Medium Product jar package name bind Highest Product Manifest Bundle-Name Old JAXB Core Medium Product pom name Old JAXB Core High Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-core Medium Version Manifest major-version 2.2.11 Medium Version Manifest build-id 2.2.11 Medium Version Manifest Implementation-Version 2.2.11 High Version Manifest Bundle-Version 2.2.11 High Version pom version 2.2.11 Highest Version file version 2.2.11 High
jaxb-core-2.2.11.jar (shaded: com.sun.istack:istack-commons-runtime:2.21)File Path: /home/frederic/.m2/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar/META-INF/maven/com.sun.istack/istack-commons-runtime/pom.xmlMD5: caebf95d1d57fc0321b36137e246e192SHA1: 04c234cf684a202c5c9bb7f0a198ba97e958f8f4SHA256: ebe7137b5fbfd050545f9a7f3f339ae55beb0b53755071b4fd62aa024c626d1cReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid istack-commons Low Vendor pom artifactid istack-commons-runtime Low Vendor pom groupid sun.istack Highest Vendor pom parent-groupid com.sun.istack Medium Vendor pom name istack common utility code runtime High Product pom artifactid istack-commons-runtime Highest Product pom groupid sun.istack Highest Product pom parent-artifactid istack-commons Medium Product pom parent-groupid com.sun.istack Medium Product pom name istack common utility code runtime High Version pom version 2.21 Highest
jaxb-core-2.2.11.jar (shaded: org.glassfish.jaxb:txw2:2.2.11)Description:
TXW is a library that allows you to write XML documents.
File Path: /home/frederic/.m2/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar/META-INF/maven/org.glassfish.jaxb/txw2/pom.xmlMD5: 83d24d59202baf2810daa01739963822SHA1: 4be03527dbf2428f7ea99fb9c2f50f089dffad5eSHA256: 8514cb724b4fca59a5cf272b632e539bd0a0f3cacf1844082d0a173a86406bd8Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom groupid glassfish.jaxb Highest Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom artifactid txw2 Low Vendor pom name TXW2 Runtime High Product pom artifactid txw2 Highest Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom groupid glassfish.jaxb Highest Product pom parent-artifactid jaxb-txw-parent Medium Product pom name TXW2 Runtime High Version pom version 2.2.11 Highest
jaxb-impl-2.2.11.jarDescription:
Old JAXB Runtime module. Contains sources required for runtime processing. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/com/sun/xml/bind/jaxb-impl/2.2.11/jaxb-impl-2.2.11.jar
MD5: bea06b3ee5ef2c338beac9187b7782f3
SHA1: a49ce57aee680f9435f49ba6ef427d38c93247a6
SHA256: f91793a96f185a2fc004c86a37086f060985854ce6b19935e03c4de51e3201d2
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom groupid com.sun.xml.bind Highest Vendor pom artifactid jaxb-impl Low Vendor Manifest originally-created-by Apache Maven 3.0.4 Low Vendor pom parent-artifactid jaxb-bundles Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom name Old JAXB Runtime High Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium Vendor pom groupid sun.xml.bind Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor jar package name bind Highest Vendor Manifest Implementation-Vendor Oracle High Vendor file name jaxb-impl High Product Manifest originally-created-by Apache Maven 3.0.4 Low Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom name Old JAXB Runtime High Product jar package name sun Highest Product Manifest specification-title Java Architecture for XML Binding Medium Product pom artifactid jaxb-impl Highest Product jar package name xml Highest Product Manifest Implementation-Title JAXB Implementation High Product Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium Product pom groupid sun.xml.bind Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom parent-artifactid jaxb-bundles Medium Product jar package name bind Highest Product Manifest Bundle-Name Old JAXB Runtime Medium Product file name jaxb-impl High Version Manifest major-version 2.2.11 Medium Version Manifest build-id 2.2.11 Medium Version Manifest Implementation-Version 2.2.11 High Version Manifest Bundle-Version 2.2.11 High Version pom version 2.2.11 Highest Version file version 2.2.11 High
jaxb-impl-2.2.11.jar (shaded: org.glassfish.jaxb:jaxb-runtime:2.2.11)Description:
JAXB (JSR 222) Reference Implementation File Path: /home/frederic/.m2/repository/com/sun/xml/bind/jaxb-impl/2.2.11/jaxb-impl-2.2.11.jar/META-INF/maven/org.glassfish.jaxb/jaxb-runtime/pom.xmlMD5: fa2e4dc2609e6a4d96418f4ac6519e8dSHA1: 6a1651361e4c2392aff30da0df648187f670f8cbSHA256: e5327b31b595ab8143e97836d5ccdf85feb91e7ff5666f7b26913632facca4aaReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom groupid glassfish.jaxb Highest Vendor pom artifactid jaxb-runtime Low Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom artifactid jaxb-runtime Highest Product pom name JAXB Runtime High Product pom groupid glassfish.jaxb Highest Product pom parent-artifactid jaxb-runtime-parent Medium Version pom version 2.2.11 Highest
jaxen-1.2.0.jarDescription:
Jaxen is a universal XPath engine for Java. License:
BSD License 2.0: https://raw.githubusercontent.com/jaxen-xpath/jaxen/master/LICENSE.txt File Path: /home/frederic/.m2/repository/jaxen/jaxen/1.2.0/jaxen-1.2.0.jar
MD5: c32cf69356254b8f5050fce6e86358e9
SHA1: c10535a925bd35129a4329bc75065cc6b5293f2c
SHA256: 70feef9dd75ad064def05a3ce8975aeba515ee7d1be146d12199c8828a64174c
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname jaxen Medium Vendor jar package name xpath Highest Vendor pom organization name The Jaxen Project High Vendor pom url http://www.cafeconleche.org/jaxen Highest Vendor Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low Vendor pom groupid jaxen Highest Vendor jar package name jaxen Highest Vendor pom organization url http://www.cafeconleche.org/jaxen Medium Vendor pom artifactid jaxen Low Vendor pom name jaxen High Vendor file name jaxen High Product jar package name xpath Highest Product Manifest Bundle-Name jaxen Medium Product Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low Product jar package name jaxen Highest Product pom groupid jaxen Highest Product pom organization name The Jaxen Project Low Product file name jaxen High Product Manifest bundle-symbolicname jaxen Medium Product pom name jaxen High Product pom url http://www.cafeconleche.org/jaxen Medium Product pom organization url http://www.cafeconleche.org/jaxen Low Product pom artifactid jaxen Highest Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version pom version 1.2.0 Highest
jersey-guava-2.25.1.jarDescription:
Jersey Guava Repackaged License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/org/glassfish/jersey/bundles/repackaged/jersey-guava/2.25.1/jersey-guava-2.25.1.jar
MD5: 08dc8642c4e990b054882cb4f422f88b
SHA1: a2bb4f8208e134cf2cf71dfb8824e42942f7bd06
SHA256: 8a88a8ebae65cb4d77830b40f681bf742b55ec62e7a44cf91b8577a9396b9f81
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jersey-guava Low Vendor pom name jersey-repackaged-guava High Vendor pom parent-groupid org.glassfish.jersey.bundles.repackaged Medium Vendor Manifest bundle-symbolicname org.glassfish.jersey.bundles.repackaged.jersey-guava Medium Vendor jar package name jersey Highest Vendor pom groupid glassfish.jersey.bundles.repackaged Highest Vendor file name jersey-guava High Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor pom groupid org.glassfish.jersey.bundles.repackaged Highest Vendor pom parent-artifactid project Low Vendor jar package name repackaged Highest Product pom name jersey-repackaged-guava High Product pom parent-groupid org.glassfish.jersey.bundles.repackaged Medium Product jar package name jersey Highest Product Manifest bundle-symbolicname org.glassfish.jersey.bundles.repackaged.jersey-guava Medium Product file name jersey-guava High Product Manifest Bundle-Name jersey-repackaged-guava Medium Product jar package name repackaged Highest Product pom artifactid jersey-guava Highest Product pom parent-artifactid project Medium Product pom groupid glassfish.jersey.bundles.repackaged Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product jar package name com Highest Version pom version 2.25.1 Highest Version file version 2.25.1 High Version Manifest Bundle-Version 2.25.1 High
Related Dependencies jersey-common-2.25.1.jarFile Path: /home/frederic/.m2/repository/org/glassfish/jersey/core/jersey-common/2.25.1/jersey-common-2.25.1.jar MD5: d1f25f421cafb38efb49e2fef0799339 SHA1: 2438ce68d4907046095ab54aa83a6092951b4bbb SHA256: 4df653fc69d5feec7ad1928018f964e12a7513bcea7b5e8b1aa4b1f5a815815f pkg:maven/org.glassfish.jersey.core/jersey-common@2.25.1 joda-time-2.10.10.jarDescription:
Date and time library to replace JDK date handling License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/joda-time/joda-time/2.10.10/joda-time-2.10.10.jar
MD5: c2a46de8a73ec7b60011429561ae72e3
SHA1: 29e8126e31f41e5c12b9fe3a7eb02e704c47d70b
SHA256: dd8e7c92185a678d1b7b933f31209b6203c8ffa91e9880475a1be0346b9617e3
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest extension-name joda-time Medium Vendor pom organization url https://www.joda.org Medium Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor pom groupid joda-time Highest Vendor Manifest implementation-url https://www.joda.org/joda-time/ Low Vendor file name joda-time High Vendor pom organization name Joda.org High Vendor Manifest automatic-module-name org.joda.time Medium Vendor Manifest specification-vendor Joda.org Low Vendor Manifest Implementation-Vendor Joda.org High Vendor pom name Joda-Time High Vendor jar package name joda Highest Vendor pom artifactid joda-time Low Vendor jar package name time Highest Vendor pom url https://www.joda.org/joda-time/ Highest Vendor Manifest bundle-symbolicname joda-time Medium Vendor Manifest bundle-docurl https://www.joda.org/joda-time/ Low Product Manifest extension-name joda-time Medium Product pom organization name Joda.org Low Product pom groupid joda-time Highest Product Manifest implementation-url https://www.joda.org/joda-time/ Low Product Manifest Bundle-Name Joda-Time Medium Product file name joda-time High Product Manifest automatic-module-name org.joda.time Medium Product Manifest Implementation-Title org.joda.time High Product pom organization url https://www.joda.org Low Product pom url https://www.joda.org/joda-time/ Medium Product pom name Joda-Time High Product jar package name joda Highest Product pom artifactid joda-time Highest Product jar package name time Highest Product Manifest bundle-symbolicname joda-time Medium Product Manifest bundle-docurl https://www.joda.org/joda-time/ Low Product Manifest specification-title Joda-Time Medium Version pom version 2.10.10 Highest Version Manifest Bundle-Version 2.10.10 High Version file version 2.10.10 High Version Manifest Implementation-Version 2.10.10 High
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.google.code.findbugs Highest Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor file name jsr305 High Vendor pom name FindBugs-jsr305 High Vendor pom url http://findbugs.sourceforge.net/ Highest Vendor pom artifactid jsr305 Low Vendor pom groupid google.code.findbugs Highest Product Manifest Bundle-Name FindBugs-jsr305 Medium Product Manifest bundle-symbolicname org.jsr-305 Medium Product file name jsr305 High Product pom name FindBugs-jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Product pom artifactid jsr305 Highest Product pom groupid google.code.findbugs Highest Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest Version file version 3.0.2 High
libthrift-0.9.3-1.jarDescription:
Thrift is a software framework for scalable cross-language services development. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/apache/thrift/libthrift/0.9.3-1/libthrift-0.9.3-1.jar
MD5: f30409cddd2782337118521abeee12c9
SHA1: 92967e32d04fd862eb679324a5c516810a5b2a28
SHA256: 6837cd6009b8401ce7ef0dcccc80c30148265f7e97cd31dc33b278a268e9471b
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor file name libthrift High Vendor pom groupid org.apache.thrift Highest Vendor Manifest bundle-symbolicname org.apache.thrift Medium Vendor pom groupid apache.thrift Highest Vendor pom name Apache Thrift High Vendor jar package name apache Highest Vendor jar package name thrift Highest Vendor Manifest bundle-activationpolicy lazy Low Vendor pom artifactid libthrift Low Vendor pom url http://thrift.apache.org Highest Product file name libthrift High Product Manifest Bundle-Name Apache Thrift Medium Product pom url http://thrift.apache.org Medium Product Manifest bundle-symbolicname org.apache.thrift Medium Product pom groupid apache.thrift Highest Product pom artifactid libthrift Highest Product pom name Apache Thrift High Product jar package name apache Highest Product jar package name thrift Highest Product Manifest bundle-activationpolicy lazy Low Version pom version 0.9.3-1 Highest Version Manifest Bundle-Version 0.9.3-1 High Version Manifest Implementation-Version 0.9.3-1 High
Published Vulnerabilities CVE-2018-11798 suppress
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path. CWE-538 File and Directory Information Exposure
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2018-1320 suppress
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-0205 suppress
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: HIGH (7.8) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-0210 suppress
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. CWE-125 Out-of-bounds Read
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-13949 suppress
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
log4j-1.2.14.jarDescription:
Log4j License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/log4j/log4j/1.2.14/log4j-1.2.14.jar
MD5: 599b8ba07d1d04f0ea34414e861d7ad1
SHA1: 03b254c872b95141751f414e353a25c2ac261b51
SHA256: e3bff9ab64a09b1ac2800f3b5fb1e3d99728064acb6dd3924938507638a404fb
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom url http://logging.apache.org/log4j/docs/ Highest Vendor pom organization name Apache Software Foundation High Vendor pom name Log4j High Vendor pom groupid log4j Highest Vendor jar package name apache Highest Vendor file name log4j High Vendor pom organization url http://www.apache.org Medium Vendor pom artifactid log4j Low Vendor jar package name log4j Highest Vendor manifest: org/apache/log4j/ Implementation-Vendor "Apache Software Foundation" Medium Product manifest: org/apache/log4j/ Implementation-Title log4j Medium Product pom artifactid log4j Highest Product pom name Log4j High Product pom url http://logging.apache.org/log4j/docs/ Medium Product pom groupid log4j Highest Product jar package name apache Highest Product file name log4j High Product pom organization name Apache Software Foundation Low Product jar package name log4j Highest Product pom organization url http://www.apache.org Low Version manifest: org/apache/log4j/ Implementation-Version 1.2.14 Medium Version file version 1.2.14 High Version pom version 1.2.14 Highest
Published Vulnerabilities CVE-2019-17571 suppress
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-9488 suppress
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. CWE-295 Improper Certificate Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
logback-core-1.2.3.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /home/frederic/.m2/repository/ch/qos/logback/logback-core/1.2.3/logback-core-1.2.3.jar
MD5: 841fc80c6edff60d947a3872a2db4d45
SHA1: 864344400c3d4d92dfeb0a305dc87d953677c03c
SHA256: 5946d837fe6f960c02a53eda7a6926ecc3c758bbdd69aa453ee429f858217f22
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name ch Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor pom parent-artifactid logback-parent Low Vendor jar package name qos Highest Vendor jar package name logback Highest Vendor pom groupid ch.qos.logback Highest Vendor file name logback-core High Vendor pom name Logback Core Module High Vendor pom artifactid logback-core Low Vendor jar package name core Highest Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid logback-core Highest Product jar package name ch Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom parent-artifactid logback-parent Medium Product jar package name logback Highest Product jar package name qos Highest Product pom groupid ch.qos.logback Highest Product file name logback-core High Product pom name Logback Core Module High Product Manifest Bundle-Name Logback Core Module Medium Product jar package name core Highest Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Version file version 1.2.3 High Version Manifest Bundle-Version 1.2.3 High Version pom version 1.2.3 Highest
Related Dependencies logback-classic-1.2.3.jarFile Path: /home/frederic/.m2/repository/ch/qos/logback/logback-classic/1.2.3/logback-classic-1.2.3.jar MD5: 64f7a68f931aed8e5ad8243470440f0b SHA1: 7c4f3c474fb2c041d8028740440937705ebb473a SHA256: fb53f8539e7fcb8f093a56e138112056ec1dc809ebb020b59d8a36a5ebac37e0 pkg:maven/ch.qos.logback/logback-classic@1.2.3 mariadb-java-client-1.7.4.jarDescription:
JDBC driver for MariaDB and MySQL License:
LGPL-2.1 File Path: /home/frederic/.m2/repository/org/mariadb/jdbc/mariadb-java-client/1.7.4/mariadb-java-client-1.7.4.jar
MD5: b9549eb5ba94a85eb1754f030657b853
SHA1: fc07a80cf17857573632d950d7387232474007ba
SHA256: bd14e9d13e79a15b6b2ad4668492d926cf7bfe7da8f5a0434f1b6b65d62a7b6a
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor pom groupid mariadb.jdbc Highest Vendor jar package name jdbc Highest Vendor pom groupid org.mariadb.jdbc Highest Vendor file name mariadb-java-client High Vendor pom url https://mariadb.com/kb/en/mariadb/about-mariadb-connector-j/ Highest Vendor jar package name mariadb Highest Vendor pom organization url https://mariadb.org Medium Vendor pom organization name mariadb.org High Vendor Manifest bundle-symbolicname org.mariadb.jdbc Medium Vendor pom artifactid mariadb-java-client Low Vendor Manifest automatic-module-name org.mariadb.jdbc Medium Vendor pom name mariadb-java-client High Product jar package name driver Highest Product pom organization name mariadb.org Low Product Manifest Bundle-Name mariadb-java-client Medium Product pom groupid mariadb.jdbc Highest Product pom organization url https://mariadb.org Low Product jar package name jdbc Highest Product file name mariadb-java-client High Product jar package name mariadb Highest Product Manifest bundle-symbolicname org.mariadb.jdbc Medium Product Manifest automatic-module-name org.mariadb.jdbc Medium Product pom url https://mariadb.com/kb/en/mariadb/about-mariadb-connector-j/ Medium Product pom name mariadb-java-client High Product pom artifactid mariadb-java-client Highest Version pom version 1.7.4 Highest Version file version 1.7.4 High Version Manifest Bundle-Version 1.7.4 High
mysql-connector-java-5.1.49.jarDescription:
MySQL JDBC Type 4 driver License:
The GNU General Public License, Version 2: http://www.gnu.org/licenses/old-licenses/gpl-2.0.html File Path: /home/frederic/.m2/repository/mysql/mysql-connector-java/5.1.49/mysql-connector-java-5.1.49.jar
MD5: b46c5a50b6d707b37bd34e27e0f6cbaf
SHA1: cf76d2e4c9c3782a85c15c87bec5772b34ffd0e5
SHA256: 5bba9ff50e5e637a0996a730619dee19ccae274883a4d28c890d945252bb0e12
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom url http://dev.mysql.com/doc/connector-j/en/ Highest Vendor Manifest bundle-symbolicname com.mysql.jdbc Medium Vendor jar package name jdbc Highest Vendor hint analyzer (hint) vendor sun Highest Vendor Manifest Implementation-Vendor-Id com.mysql Medium Vendor file name mysql-connector-java High Vendor jar package name mysql Highest Vendor pom organization url http://www.oracle.com Medium Vendor pom artifactid mysql-connector-java Low Vendor pom name MySQL Connector/J High Vendor hint analyzer vendor oracle Highest Vendor pom groupid mysql Highest Vendor Manifest Implementation-Vendor Oracle High Vendor pom organization name Oracle Corporation High Product jar package name driver Highest Product Manifest bundle-symbolicname com.mysql.jdbc Medium Product pom artifactid mysql-connector-java Highest Product jar package name jdbc Highest Product hint analyzer product mysql_connectors Highest Product hint analyzer product mysql_connector_j Highest Product file name mysql-connector-java High Product pom organization name Oracle Corporation Low Product jar package name mysql Highest Product Manifest specification-title JDBC Medium Product Manifest Implementation-Title MySQL Connector Java High Product pom name MySQL Connector/J High Product Manifest Bundle-Name Oracle Corporation's JDBC Driver for MySQL Medium Product pom organization url http://www.oracle.com Low Product pom groupid mysql Highest Product hint analyzer product mysql_connector/j Highest Product pom url http://dev.mysql.com/doc/connector-j/en/ Medium Version file version 5.1.49 High Version pom version 5.1.49 Highest Version Manifest Implementation-Version 5.1.49 High Version Manifest Bundle-Version 5.1.49 High
Published Vulnerabilities CVE-2017-15945 suppress
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: HIGH (7.2) Vector: /AV:L/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-3258 (OSSINDEX) suppress
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:mysql:mysql-connector-java:5.1.49:*:*:*:*:*:*:* CVE-2019-2692 suppress
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H). NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:L/AC:H/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: MEDIUM (6.3) Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
netty-all-4.1.59.Final.jarFile Path: /home/frederic/.m2/repository/io/netty/netty-all/4.1.59.Final/netty-all-4.1.59.Final.jarMD5: 20d0265af69d43d65093d152d1ac5f51SHA1: 4d83eab2c554587e15fa9cc20de48c530b23c479SHA256: c483e8103dbce2a4b57e0b99ea2c128a29b57be677ee62e44d767fa425c3fe7aReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name io Highest Vendor pom artifactid netty-all Low Vendor pom parent-artifactid netty-parent Low Vendor Manifest automatic-module-name io.netty.all Medium Vendor Manifest Implementation-Vendor-Id io.netty Medium Vendor jar package name netty Highest Vendor pom name Netty/All-in-One High Vendor pom groupid io.netty Highest Vendor Manifest Implementation-Vendor The Netty Project High Vendor file name netty-all High Vendor Manifest implementation-url https://netty.io/netty-all/ Low Product jar package name io Highest Product Manifest Implementation-Title Netty/All-in-One High Product Manifest automatic-module-name io.netty.all Medium Product jar package name netty Highest Product pom name Netty/All-in-One High Product pom groupid io.netty Highest Product pom artifactid netty-all Highest Product file name netty-all High Product Manifest implementation-url https://netty.io/netty-all/ Low Product pom parent-artifactid netty-parent Medium Version pom version 4.1.59.Final Highest Version Manifest Implementation-Version 4.1.59.Final High
netty-http-java6-1.5.0.jarDescription:
Waarp shaded jar for Netty HTTP Router for Java 6 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/Waarp/netty-http-java6/1.5.0/netty-http-java6-1.5.0.jar
MD5: c626a48ebeb6d2c0dfea9953a1db333b
SHA1: 11a3759b842014ccadd544dd58c9320a44ff41a1
SHA256: 6676f2f137eace2c32a534567d92c2167aa9e27cc47de585c5d79e7e32bdf373
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid netty-http-java6 Low Vendor pom name Netty based path router Shaded for Java6 High Vendor file name netty-http-java6 High Vendor pom groupid Waarp Highest Vendor pom url cdapio/netty-http Highest Vendor jar package name http Highest Vendor pom parent-artifactid Waarp-Shaded-Parent Low Product Manifest build-jdk-spec 1.8 Low Product pom name Netty based path router Shaded for Java6 High Product pom parent-artifactid Waarp-Shaded-Parent Medium Product pom artifactid netty-http-java6 Highest Product file name netty-http-java6 High Product pom groupid Waarp Highest Product pom url cdapio/netty-http High Product jar package name http Highest Version file version 1.5.0 High Version pom parent-version 1.5.0 Low Version pom version 1.5.0 Highest
netty-tcnative-boringssl-static-2.0.36.Final.jarDescription:
A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
to BoringSSL and Apache APR.
File Path: /home/frederic/.m2/repository/io/netty/netty-tcnative-boringssl-static/2.0.36.Final/netty-tcnative-boringssl-static-2.0.36.Final.jarMD5: 61fca971d9f1175e934d5c01d3fcabebSHA1: f35f05118d846dfe30a4e7f757a47601ee9d0ceaSHA256: 2c0d55797dbfcb3d8639eab4957b37a8d7982f32196f029b25a2ff0e326f118fReferenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name io Highest Vendor pom parent-artifactid netty-tcnative-parent Low Vendor Manifest automatic-module-name io.netty.tcnative.boringssl Medium Vendor pom name Netty/TomcatNative [BoringSSL - Static] High Vendor file name netty-tcnative-boringssl-static High Vendor jar package name netty Highest Vendor jar package name tcnative Highest Vendor pom groupid io.netty Highest Vendor pom artifactid netty-tcnative-boringssl-static Low Product jar package name io Highest Product pom artifactid netty-tcnative-boringssl-static Highest Product Manifest automatic-module-name io.netty.tcnative.boringssl Medium Product pom name Netty/TomcatNative [BoringSSL - Static] High Product file name netty-tcnative-boringssl-static High Product jar package name netty Highest Product jar package name tcnative Highest Product pom groupid io.netty Highest Product pom parent-artifactid netty-tcnative-parent Medium Version pom version 2.0.36.Final Highest
osgi-resource-locator-1.0.1.jarDescription:
See http://wiki.glassfish.java.net/Wiki.jsp?page=JdkSpiOsgi for more information License:
https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /home/frederic/.m2/repository/org/glassfish/hk2/osgi-resource-locator/1.0.1/osgi-resource-locator-1.0.1.jar
MD5: 51e70ad8fc9d1e9fb19debeb55555b75
SHA1: 4ed2b2d4738aed5786cfa64cba5a332779c4c708
SHA256: 775003be577e8806f51b6e442be1033d83be2cb2207227b349be0bf16e6c0843
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low Vendor jar package name glassfish Highest Vendor pom groupid glassfish.hk2 Highest Vendor file name osgi-resource-locator High Vendor pom groupid org.glassfish.hk2 Highest Vendor Manifest bundle-activationpolicy lazy Low Vendor pom name OSGi resource locator bundle - used by various API providers that rely on META-INF/services mechanism to locate providers. High Vendor pom artifactid osgi-resource-locator Low Vendor Manifest bundle-symbolicname org.glassfish.hk2.osgi-resource-locator Medium Vendor jar package name hk2 Highest Vendor pom parent-groupid org.glassfish Medium Vendor pom parent-artifactid pom Low Product Manifest bundle-docurl https://glassfish.dev.java.net Low Product pom artifactid osgi-resource-locator Highest Product jar package name glassfish Highest Product pom groupid glassfish.hk2 Highest Product file name osgi-resource-locator High Product Manifest Bundle-Name OSGi resource locator bundle - used by various API providers that rely on META-INF/services mechanism to locate providers. Medium Product Manifest bundle-activationpolicy lazy Low Product pom name OSGi resource locator bundle - used by various API providers that rely on META-INF/services mechanism to locate providers. High Product Manifest bundle-symbolicname org.glassfish.hk2.osgi-resource-locator Medium Product pom parent-artifactid pom Medium Product jar package name hk2 Highest Product pom parent-groupid org.glassfish Medium Version pom version 1.0.1 Highest Version Manifest Bundle-Version 1.0.1 High Version pom parent-version 1.0.1 Low Version file version 1.0.1 High
postgresql-42.2.19.jre6.jarDescription:
PostgreSQL JDBC Driver Postgresql-jre6 License:
BSD-2-Clause: https://jdbc.postgresql.org/about/license.html File Path: /home/frederic/.m2/repository/org/postgresql/postgresql/42.2.19.jre6/postgresql-42.2.19.jre6.jar
MD5: 3b73434467f488892dffe8948be277b1
SHA1: 3af16b10c6854d42389dffdeb5ca3aa6846c2095
SHA256: 2467bbbb47b868e4ef801b6d20cfd76a0e6dfb8599df2e5d63a0521245cd4e0d
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor pom groupid org.postgresql Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor pom name pgdjbc Postgresql-jre6 High Vendor pom url https://jdbc.postgresql.org Highest Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor jar package name postgresql Highest Vendor Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Vendor pom organization name PostgreSQL Global Development Group High Vendor Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.6))" Low Vendor jar package name jdbc Highest Vendor pom organization url https://jdbc.postgresql.org/ Medium Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor pom artifactid postgresql Low Vendor file name postgresql High Vendor pom groupid postgresql Highest Product jar package name driver Highest Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product pom name pgdjbc Postgresql-jre6 High Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product pom url https://jdbc.postgresql.org Medium Product jar package name postgresql Highest Product Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Product pom organization url https://jdbc.postgresql.org/ Low Product pom artifactid postgresql Highest Product jar package name version Highest Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.6))" Low Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product jar package name jdbc Highest Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Product jar package name osgi Highest Product Manifest specification-title JDBC Medium Product file name postgresql High Product pom organization name PostgreSQL Global Development Group Low Product pom groupid postgresql Highest Version Manifest Bundle-Version 42.2.19.jre6 High Version Manifest Implementation-Version 42.2.19.jre6 High Version file version 42.2.19.jre6 High Version pom version 42.2.19.jre6 Highest
slf4j-api-1.7.30.jarDescription:
The slf4j API File Path: /home/frederic/.m2/repository/org/slf4j/slf4j-api/1.7.30/slf4j-api-1.7.30.jarMD5: f8be00da99bc4ab64c79ab1e2be7cb7cSHA1: b5a4b6d16ab13e34a88fae84c35cd5d68cac922cSHA256: cdba07964d1bb40a0761485c6b1e8c2f8fd9eb1d19c53928ac0d7f9510105c57Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest automatic-module-name org.slf4j Medium Vendor jar package name slf4j Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor file name slf4j-api High Vendor pom parent-groupid org.slf4j Medium Vendor pom artifactid slf4j-api Low Vendor pom url http://www.slf4j.org Highest Product pom groupid slf4j Highest Product pom name SLF4J API Module High Product Manifest Bundle-Name slf4j-api Medium Product pom url http://www.slf4j.org Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest automatic-module-name org.slf4j Medium Product jar package name slf4j Highest Product Manifest Implementation-Title slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product file name slf4j-api High Product pom parent-groupid org.slf4j Medium Product pom parent-artifactid slf4j-parent Medium Product pom artifactid slf4j-api Highest Version pom version 1.7.30 Highest Version Manifest Bundle-Version 1.7.30 High Version file version 1.7.30 High Version Manifest Implementation-Version 1.7.30 High
snmp4j-2.6.3.jarDescription:
SNMP API for Java License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/snmp4j/snmp4j/2.6.3/snmp4j-2.6.3.jar
MD5: 3fbdac27dfc57221dfc8c2dd3e1ef7e7
SHA1: 6e30241759ed24efe9b64944ed52467122bafafa
SHA256: 65cfa42dfe346bc991cbd3eb9e8356269f288c98cc12a423263ffcb78324a784
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid snmp4j Highest Vendor pom name SNMP4J High Vendor jar package name snmp Highest Vendor file name snmp4j High Vendor pom organization name SNMP4J.org High Vendor pom url http://www.snmp4j.org Highest Vendor pom organization url http://www.snmp4j.org Medium Vendor pom groupid org.snmp4j Highest Vendor jar package name snmp4j Highest Vendor pom artifactid snmp4j Low Vendor jar package name snmp4j Low Product pom url http://www.snmp4j.org Medium Product pom groupid snmp4j Highest Product pom organization name SNMP4J.org Low Product pom name SNMP4J High Product jar package name snmp Highest Product pom artifactid snmp4j Highest Product file name snmp4j High Product jar package name snmp4j Highest Product pom organization url http://www.snmp4j.org Low Version pom version 2.6.3 Highest Version file version 2.6.3 High
snmp4j-agent-2.6.3.jarDescription:
SNMP-Agent API for Java License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/snmp4j/snmp4j-agent/2.6.3/snmp4j-agent-2.6.3.jar
MD5: 04b124cd7e7edb42ffbf23c4335a3e64
SHA1: 92ca6fedf945342a0b479963dd9c0a3700046335
SHA256: 75646cbcc9a3b742e7bdd0b86226d8ab3eb0d473d230a4e013b601bbb8a0ffdf
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom name SNMP4J-Agent High Vendor jar package name mo Low Vendor pom groupid snmp4j Highest Vendor pom organization name SNMP4J.org High Vendor jar package name agent Highest Vendor jar package name agent Low Vendor jar package name snmp4j Highest Vendor jar package name snmp4j Low Vendor file name snmp4j-agent High Vendor jar package name snmp Highest Vendor pom url http://www.snmp4j.org Highest Vendor pom organization url http://www.snmp4j.org Medium Vendor pom groupid org.snmp4j Highest Vendor pom artifactid snmp4j-agent Low Product pom name SNMP4J-Agent High Product jar package name mo Low Product pom groupid snmp4j Highest Product jar package name agent Highest Product pom artifactid snmp4j-agent Highest Product jar package name agent Low Product jar package name snmp4j Highest Product pom url http://www.snmp4j.org Medium Product pom organization name SNMP4J.org Low Product file name snmp4j-agent High Product jar package name snmp Highest Product pom organization url http://www.snmp4j.org Low Version pom version 2.6.3 Highest Version file version 2.6.3 High
xercesImpl-2.12.1.jarDescription:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family.
This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building
parser components and configurations that is extremely modular and easy to program. The Apache Xerces2 parser is
the reference implementation of XNI but other parser components, configurations, and parsers can be written
using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.
Xerces2 is a fully conforming XML Schema 1.0 processor. A partial experimental implementation of the XML Schema
1.1 Structures and Datatypes Working Drafts (December 2009) and an experimental implementation of the XML Schema
Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010) are provided for
evaluation. For more information, refer to the XML Schema page. Xerces2 also provides a complete implementation
of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete
implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML
Catalogs v1.1. Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that
it does not yet provide an option to enable normalization checking as described in section 2.13 of this
specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly
serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/exist-db/thirdparty/xerces/xercesImpl/2.12.1/xercesImpl-2.12.1.jar
MD5: 9f82c362c893779109c1de812c5d4deb
SHA1: 3a206b25679f598a03374afd4e0410d8849b088b
SHA256: ae0c329a3187178c8e7b0369a5346845e426062ffbb8a08fc68ced6affe6c626
Referenced In Project/Scope: Waarp Administrator:compile
Evidence Type Source Name Value Confidence Vendor pom groupid exist-db.thirdparty.xerces Highest Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xerces/impl/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor pom url https://xerces.apache.org/xerces2-j/ Highest Vendor pom name Xerces2-j High Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name parsers Highest Vendor jar package name xml Highest Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor jar package name datatypes Highest Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name xinclude Highest Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name dom Highest Vendor jar package name version Highest Vendor jar package name xni Highest Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name serialize Highest Vendor jar package name w3c Highest Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name xerces Highest Vendor file name xercesImpl High Vendor pom artifactid xercesImpl Low Vendor jar package name apache Highest Vendor pom groupid org.exist-db.thirdparty.xerces Highest Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product pom groupid exist-db.thirdparty.xerces Highest Product pom name Xerces2-j High Product manifest: org/apache/xerces/impl/ Implementation-Title org.apache.xerces.impl.Version Medium Product jar package name impl Highest Product jar package name parsers Highest Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium Product jar package name xml Highest Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium Product jar package name datatypes Highest Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML Medium Product jar package name xinclude Highest Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Product jar package name xpath Highest Product pom artifactid xercesImpl Highest Product jar package name datatype Highest Product jar package name dom Highest Product jar package name xni Highest Product jar package name version Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product jar package name serialize Highest Product jar package name w3c Highest Product jar package name xerces Highest Product file name xercesImpl High Product jar package name validation Highest Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product jar package name apache Highest Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product pom url https://xerces.apache.org/xerces2-j/ Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing Medium Version file version 2.12.1 High Version pom version 2.12.1 Highest Version manifest: org/apache/xerces/impl/ Implementation-Version 2.12.1 Medium
Published Vulnerabilities CVE-2018-1000823 suppress
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (10.0) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )