Логотип exploitDog
bind:CVE-2019-3873
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-3873

Количество 4

Количество 4

redhat логотип

CVE-2019-3873

больше 6 лет назад

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2019-3873

больше 6 лет назад

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-59jq-66fv-jgww

больше 3 лет назад

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 9
EPSS: Низкий
fstec логотип

BDU:2020-04802

больше 6 лет назад

Уязвимость компонента Picketlink платформы JBoss Enterprise Application Platform, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 6.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 6.4
0%
Низкий
больше 6 лет назад
github логотип
GHSA-59jq-66fv-jgww

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

CVSS3: 9
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-04802

Уязвимость компонента Picketlink платформы JBoss Enterprise Application Platform, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 9
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу