Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : Oct 13, 2019 at 07:54:11 +00:00
Dependencies Scanned : 248 (207 unique)
Vulnerable Dependencies : 30
Vulnerabilities Found : 73
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 10/10/2019 09:15:36
NVD CVE 2003 : 11/10/2019 08:45:55
NVD CVE 2004 : 08/10/2019 13:32:07
NVD CVE 2005 : 11/10/2019 08:45:55
NVD CVE 2006 : 11/10/2019 08:45:55
NVD CVE 2007 : 10/10/2019 09:15:36
NVD CVE 2008 : 11/10/2019 08:45:55
NVD CVE 2009 : 11/10/2019 08:45:55
NVD CVE 2010 : 12/10/2019 08:45:35
NVD CVE 2011 : 10/10/2019 08:45:44
NVD CVE 2012 : 10/10/2019 08:45:45
NVD CVE 2013 : 11/10/2019 08:45:56
NVD CVE 2014 : 10/10/2019 08:45:45
NVD CVE 2015 : 12/10/2019 08:45:35
NVD CVE 2016 : 12/10/2019 08:15:30
NVD CVE 2017 : 12/10/2019 08:15:30
NVD CVE 2018 : 12/10/2019 07:45:35
NVD CVE 2019 : 12/10/2019 07:45:35
NVD CVE Checked : 13/10/2019 07:53:12
NVD CVE Modified : 13/10/2019 05:15:31
VersionCheckOn : 1570953192127
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Day Software Management AG High
Vendor pom groupid javax.jcr Highest
Vendor pom organization url http://www.day.com/ Medium
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor file name jcr High
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor pom artifactid jcr Low
Vendor pom name Content Repository for Java Technology API High
Vendor Manifest extension-name jcr Medium
Vendor pom organization name Day Software Management AG High
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product Manifest specification-title Content Repository for Java Technology API Medium
Product pom organization url http://www.day.com/ Low
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom artifactid jcr Highest
Product file name jcr High
Product pom groupid javax.jcr Low
Product Manifest Implementation-Title javax.jcr High
Product pom organization name Day Software Management AG Low
Product pom name Content Repository for Java Technology API High
Product Manifest extension-name jcr Medium
Version pom version 1.0.1 Highest
Version file version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
commons-chain-1.2.jar
Description:
An implementation of the GoF Chain of Responsibility pattern
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-chain/commons-chain/1.2/commons-chain-1.2.jar
MD5: e18e2c87826644e4c8c08635572c154f
SHA1: 744a13e8766e338bd347b6fbc28c6db12979d0c6
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Vendor pom name Commons Chain High
Vendor pom artifactid commons-chain Low
Vendor pom url http://commons.apache.org/chain/ Highest
Vendor central groupid commons-chain Highest
Vendor pom groupid commons-chain Highest
Vendor pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor file name commons-chain High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-symbolicname org.apache.commons.chain Medium
Vendor Manifest bundle-docurl http://commons.apache.org/chain/ Low
Product manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Product pom name Commons Chain High
Product pom artifactid commons-chain Highest
Product Manifest specification-title Commons Chain Medium
Product pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Product pom url http://commons.apache.org/chain/ Medium
Product Manifest Bundle-Name Commons Chain Medium
Product file name commons-chain High
Product pom parent-groupid org.apache.commons Low
Product Manifest bundle-symbolicname org.apache.commons.chain Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/chain/ Low
Product central artifactid commons-chain Highest
Product Manifest Implementation-Title Commons Chain High
Product pom groupid commons-chain Low
Version Manifest Implementation-Version 1.2 High
Version pom version 1.2 Highest
Version file version 1.2 Highest
Version central version 1.2 Highest
commons-digester-2.1.jar
Description:
The Digester package lets you configure an XML to Java object mapping module
which triggers certain actions called rules whenever a particular
pattern of nested XML elements is recognized.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest bundle-docurl http://commons.apache.org/digester/ Low
Vendor pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor file name commons-digester High
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url http://commons.apache.org/digester/ Highest
Vendor pom groupid commons-digester Highest
Vendor manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor Manifest bundle-symbolicname org.apache.commons.digester Medium
Vendor pom artifactid commons-digester Low
Vendor central groupid commons-digester Highest
Vendor pom name Commons Digester High
Product pom artifactid commons-digester Highest
Product Manifest bundle-docurl http://commons.apache.org/digester/ Low
Product central artifactid commons-digester Highest
Product pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product file name commons-digester High
Product Manifest Implementation-Title Commons Digester High
Product pom groupid commons-digester Low
Product pom parent-groupid org.apache.commons Low
Product Manifest Bundle-Name Commons Digester Medium
Product manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-symbolicname org.apache.commons.digester Medium
Product pom url http://commons.apache.org/digester/ Medium
Product Manifest specification-title Commons Digester Medium
Product pom name Commons Digester High
Version pom version 2.1 Highest
Version Manifest Implementation-Version 2.1 High
Version file version 2.1 Highest
Version central version 2.1 Highest
exo.kernel.component.command-6.0.x-SNAPSHOT.jar
Description: Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.command/6.0.x-SNAPSHOT/exo.kernel.component.command-6.0.x-SNAPSHOT.jar
MD5: 6cd704efa2fd1fb9be83bdb727c5815d
SHA1: 7eec89696a2fa5e0eaf724e1b2468594e26f6bcf
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.command Low
Vendor pom name eXo PLF:: Kernel :: Component :: Command Service High
Vendor pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid kernel-parent Low
Vendor file name exo.kernel.component.command High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Command Service High
Product pom name eXo PLF:: Kernel :: Component :: Command Service High
Product pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product Manifest specification-title exo-kernel Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom artifactid exo.kernel.component.command Highest
Product file name exo.kernel.component.command High
Version pom version 6.0.x-20191006.135443-6 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.command:6.0.x-SNAPSHOT
Confidence :High
mail-1.4.7.jar
Description: JavaMail API (compat)
License:
http://www.sun.com/cddl, https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/ciagent/.m2/repository/javax/mail/mail/1.4.7/mail-1.4.7.jar
MD5: 77f53ff0c78ba43c4812ecc9f53e20f8
SHA1: 9add058589d5d85adeb625859bf2c5eeaaedf12d
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Oracle High
Vendor file name mail High
Vendor pom parent-artifactid all Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest extension-name javax.mail Medium
Vendor central groupid javax.mail High
Vendor pom parent-groupid com.sun.mail Medium
Vendor Manifest specification-vendor Oracle Low
Vendor manifest Bundle-Description JavaMail API (compat) Medium
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor Manifest bundle-symbolicname javax.mail Medium
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor pom artifactid mail Low
Vendor Manifest (hint) specification-vendor sun Low
Vendor pom name JavaMail API (compat) High
Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Vendor Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Vendor pom groupid javax.mail Highest
Product Manifest Bundle-Name JavaMail API (compat) Medium
Product file name mail High
Product Manifest extension-name javax.mail Medium
Product pom groupid javax.mail Low
Product manifest Bundle-Description JavaMail API (compat) Medium
Product Manifest bundle-symbolicname javax.mail Medium
Product Manifest specification-title JavaMail(TM) API Design Specification Medium
Product Manifest Implementation-Title javax.mail High
Product Manifest bundle-docurl http://www.oracle.com Low
Product central artifactid mail High
Product pom parent-groupid com.sun.mail Low
Product pom artifactid mail Highest
Product pom name JavaMail API (compat) High
Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Product Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Product pom parent-artifactid all Medium
Product central artifactid mail-1.4.7 High
Version file version 1.4.7 Highest
Version Manifest Implementation-Version 1.4.7 High
commons-dbcp-1.4.jar
Description: Commons Database Connection Pooling
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:runtime
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - Juzu Bridge for Platform:runtime
eXo PLF:: Commons - Commons WebUI:runtime
eXo PLF:: Commons - WebUI Extension:runtime
eXo PLF:: Commons - Product Informations:runtime
eXo PLF:: Commons - Comet Services:runtime
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:runtime
eXo PLF:: Commons - Comet Ext Service (test only):runtime
eXo PLF:: Commons - Common Services:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Vendor pom description Commons Database Connection Pooling Medium
Vendor Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor file name commons-dbcp High
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description Commons Database Connection Pooling Medium
Vendor pom groupid commons-dbcp Highest
Vendor pom name Commons DBCP High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom artifactid commons-dbcp Low
Vendor central groupid commons-dbcp Highest
Vendor pom url http://commons.apache.org/dbcp/ Highest
Product Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Product pom description Commons Database Connection Pooling Medium
Product pom url http://commons.apache.org/dbcp/ Medium
Product central artifactid commons-dbcp Highest
Product Manifest Bundle-Name Commons DBCP Medium
Product Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Product Manifest Implementation-Title Commons DBCP High
Product file name commons-dbcp High
Product manifest Bundle-Description Commons Database Connection Pooling Medium
Product pom name Commons DBCP High
Product pom groupid commons-dbcp Low
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-dbcp Highest
Product Manifest specification-title Commons DBCP Medium
Version central version 1.4 Highest
Version file version 1.4 Highest
Version pom version 1.4 Highest
Version Manifest Implementation-Version 1.4 High
commons-pool-1.6.jar
Description: Commons Object Pooling Library
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:runtime
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - Juzu Bridge for Platform:runtime
eXo PLF:: Commons - Commons WebUI:runtime
eXo PLF:: Commons - WebUI Extension:runtime
eXo PLF:: Commons - Product Informations:runtime
eXo PLF:: Commons - Comet Services:runtime
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:runtime
eXo PLF:: Commons - Comet Ext Service (test only):runtime
eXo PLF:: Commons - Common Services:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom description Commons Object Pooling Library Medium
Vendor pom url http://commons.apache.org/pool/ Highest
Vendor pom name Commons Pool High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-pool Highest
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-pool Low
Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium
Vendor manifest Bundle-Description Commons Object Pooling Library Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-pool Highest
Vendor file name commons-pool High
Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low
Product Manifest Implementation-Title Commons Pool High
Product pom description Commons Object Pooling Library Medium
Product Manifest Bundle-Name Commons Pool Medium
Product pom name Commons Pool High
Product central artifactid commons-pool Highest
Product Manifest specification-title Commons Pool Medium
Product pom groupid commons-pool Low
Product pom artifactid commons-pool Highest
Product Manifest bundle-symbolicname org.apache.commons.pool Medium
Product manifest Bundle-Description Commons Object Pooling Library Medium
Product pom parent-groupid org.apache.commons Low
Product pom url http://commons.apache.org/pool/ Medium
Product pom parent-artifactid commons-parent Medium
Product file name commons-pool High
Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Product Manifest bundle-docurl http://commons.apache.org/pool/ Low
Version Manifest Implementation-Version 1.6 High
Version pom version 1.6 Highest
Version file version 1.6 Highest
Version central version 1.6 Highest
exo.kernel.component.common-6.0.x-SNAPSHOT.jar
Description: Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.common/6.0.x-SNAPSHOT/exo.kernel.component.common-6.0.x-SNAPSHOT.jar
MD5: 7d56b2a5181e482b340b4f0e9ee5e017
SHA1: bb1382baadbd0dd13685e7cc493f37dcf551896d
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom name eXo PLF:: Kernel :: Component :: Common Service High
Vendor pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor file name exo.kernel.component.common High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid kernel-parent Low
Vendor pom artifactid exo.kernel.component.common Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product pom name eXo PLF:: Kernel :: Component :: Common Service High
Product pom artifactid exo.kernel.component.common Highest
Product pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product file name exo.kernel.component.common High
Product Manifest specification-title exo-kernel Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Common Service High
Product pom parent-groupid org.exoplatform.kernel Low
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.common:6.0.x-SNAPSHOT
Confidence :High
exo.kernel.component.cache-6.0.x-SNAPSHOT.jar
Description: Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.cache/6.0.x-SNAPSHOT/exo.kernel.component.cache-6.0.x-SNAPSHOT.jar
MD5: 8b0d5bca7bccac22c8b49202e3af31d4
SHA1: fc7fd420984fb3a4f426029ce1353149fab42d35
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.cache Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid kernel-parent Low
Vendor pom name eXo PLF:: Kernel :: Component :: Cache Service High
Vendor file name exo.kernel.component.cache High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Cache Service High
Product pom parent-artifactid kernel-parent Medium
Product pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product Manifest specification-title exo-kernel Medium
Product pom artifactid exo.kernel.component.cache Highest
Product pom parent-groupid org.exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Component :: Cache Service High
Product file name exo.kernel.component.cache High
Version pom version 6.0.x-20191006.135353-6 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.cache:6.0.x-SNAPSHOT
Confidence :High
exo.core.component.security.core-6.0.x-SNAPSHOT.jar
Description: Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.security.core/6.0.x-SNAPSHOT/exo.core.component.security.core-6.0.x-SNAPSHOT.jar
MD5: ed9e42743794ca109fb30bfe6543b076
SHA1: 1a774aae09ac563ecf77c7c78153a60c9c8e6bd0
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF Core :: Component :: Security Service High
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor file name exo.core.component.security.core High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor pom artifactid exo.core.component.security.core Low
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Product pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest specification-title exo-core Medium
Product pom name eXo PLF Core :: Component :: Security Service High
Product pom artifactid exo.core.component.security.core Highest
Product pom parent-artifactid core-parent Medium
Product file name exo.core.component.security.core High
Product pom groupid exoplatform.core Low
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: Security Service High
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.security.core:6.0.x-SNAPSHOT
Confidence :High
antlr-2.7.7.jar
Description:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html
File Path: /home/ciagent/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor jar package name antlr Low
Vendor central groupid antlr Highest
Vendor file name antlr High
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor pom groupid antlr Highest
Vendor pom artifactid antlr Low
Vendor pom name AntLR Parser Generator High
Vendor pom url http://www.antlr.org/ Highest
Product file name antlr High
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom artifactid antlr Highest
Product pom groupid antlr Low
Product pom url http://www.antlr.org/ Medium
Product pom name AntLR Parser Generator High
Product central artifactid antlr Highest
Version file version 2.7.7 Highest
Version central version 2.7.7 Highest
Version pom version 2.7.7 Highest
dom4j-1.6.1.jar
Description: dom4j: the flexible XML framework for Java
File Path: /home/ciagent/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor MetaStuff Ltd. High
Vendor pom artifactid dom4j Low
Vendor pom description dom4j: the flexible XML framework for Java Medium
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor Manifest specification-vendor MetaStuff Ltd. Low
Vendor pom groupid dom4j Highest
Vendor pom organization name MetaStuff Ltd. High
Vendor pom organization url http://sourceforge.net/projects/dom4j Medium
Vendor pom url http://dom4j.org Highest
Vendor file name dom4j High
Vendor central groupid dom4j High
Vendor pom name dom4j High
Vendor Manifest extension-name dom4j Medium
Product pom organization name MetaStuff Ltd. Low
Product pom artifactid dom4j Highest
Product central artifactid dom4j High
Product pom description dom4j: the flexible XML framework for Java Medium
Product pom groupid dom4j Low
Product pom url http://dom4j.org Medium
Product file name dom4j High
Product pom organization url http://sourceforge.net/projects/dom4j Low
Product Manifest specification-title dom4j : XML framework for Java Medium
Product pom name dom4j High
Product Manifest extension-name dom4j Medium
Product central artifactid dom4j-1.6.1 High
Product Manifest Implementation-Title org.dom4j High
Version Manifest Implementation-Version 1.6.1 High
Version file version 1.6.1 Highest
Published Vulnerabilities
CVE-2018-1000632 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Vulnerable Software & Versions: (show all )
hibernate-jpa-2.0-api-1.0.1.Final.jar
Description:
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
License:
license.txt
File Path: /home/ciagent/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.0-api/1.0.1.Final/hibernate-jpa-2.0-api-1.0.1.Final.jar
MD5: d7e7d8f60fc44a127ba702d43e71abec
SHA1: 3306a165afa81938fc3d8a0948e891de9f6b192b
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name hibernate-jpa-2.0-api-1.0.1.Final High
Vendor pom groupid hibernate.javax.persistence Highest
Vendor pom organization name Hibernate.org High
Vendor pom artifactid hibernate-jpa-2.0-api Low
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor Manifest Implementation-Vendor hibernate.org High
Vendor central groupid org.hibernate.javax.persistence Highest
Vendor pom name JPA 2.0 API High
Vendor pom url http://hibernate.org Highest
Vendor pom groupid org.hibernate.javax.persistence Highest
Vendor pom organization url http://hibernate.org Medium
Vendor pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product file name hibernate-jpa-2.0-api-1.0.1.Final High
Product Manifest specification-title Java Persistence API, Version 2.0 Medium
Product pom name JPA 2.0 API High
Product pom groupid hibernate.javax.persistence Low
Product central artifactid hibernate-jpa-2.0-api Highest
Product pom url http://hibernate.org Medium
Product pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product pom artifactid hibernate-jpa-2.0-api Highest
Product pom organization name Hibernate.org Low
Product Manifest Implementation-Title JPA API High
Product pom organization url http://hibernate.org Low
Version central version 1.0.1.Final Highest
Version pom version 1.0.1.Final Highest
Version Manifest Implementation-Version 1.0.1.Final High
jboss-logging-annotations-1.2.0.Beta1.jar
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging-annotations/1.2.0.Beta1/jboss-logging-annotations-1.2.0.Beta1.jar
MD5: 938e552e319015a8863dd91284aada54
SHA1: 2f437f37bb265d9f8f1392823dbca12d2bec06d6
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom artifactid jboss-logging-annotations Low
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor pom name JBoss Logging I18n Annotations High
Vendor Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Vendor file name jboss-logging-annotations High
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor central groupid org.jboss.logging Highest
Vendor Manifest os-name Linux Medium
Vendor pom parent-groupid org.jboss.logging Medium
Vendor pom groupid jboss.logging Highest
Vendor Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Vendor pom groupid org.jboss.logging Highest
Product pom artifactid jboss-logging-annotations Highest
Product central artifactid jboss-logging-annotations Highest
Product pom name JBoss Logging I18n Annotations High
Product Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Product pom parent-groupid org.jboss.logging Low
Product file name jboss-logging-annotations High
Product Manifest specification-title JBoss Logging I18n Annotations Medium
Product Manifest Implementation-Title JBoss Logging I18n Annotations High
Product Manifest os-name Linux Medium
Product pom groupid jboss.logging Low
Product Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Product pom parent-artifactid jboss-logging-tools-parent Medium
Version pom version 1.2.0.Beta1 Highest
Version Manifest Implementation-Version 1.2.0.Beta1 High
Version central version 1.2.0.Beta1 Highest
hibernate-commons-annotations-4.0.5.Final.jar
Description: Common reflection code used in support of annotation processing
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/common/hibernate-commons-annotations/4.0.5.Final/hibernate-commons-annotations-4.0.5.Final.jar
MD5: 5dadbafd7c7bc1168c10a2ba87e927a2
SHA1: 2a581b9edb8168e45060d8bad8b7f46712d2c52c
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid hibernate.common Highest
Vendor pom organization name Hibernate.org High
Vendor central groupid org.hibernate.common Highest
Vendor pom groupid org.hibernate.common Highest
Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Vendor pom artifactid hibernate-commons-annotations Low
Vendor pom name Hibernate Commons Annotations High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom description Common reflection code used in support of annotation processing Medium
Vendor pom url http://hibernate.org Highest
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor file name hibernate-commons-annotations High
Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Product pom artifactid hibernate-commons-annotations Highest
Product pom name Hibernate Commons Annotations High
Product pom organization name Hibernate.org Low
Product pom organization url http://hibernate.org Low
Product Manifest implementation-url http://hibernate.org Low
Product pom description Common reflection code used in support of annotation processing Medium
Product central artifactid hibernate-commons-annotations Highest
Product pom url http://hibernate.org Medium
Product file name hibernate-commons-annotations High
Product Manifest Bundle-Name hibernate-commons-annotations Medium
Product pom groupid hibernate.common Low
Version file version 4.0.5 Highest
Version central version 4.0.5.Final Highest
Version Manifest Implementation-Version 4.0.5.Final High
Version pom version 4.0.5.Final Highest
hibernate-core-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-core/4.2.21.Final/hibernate-core-4.2.21.Final.jar
MD5: 492567c1f36fb3a5968ca2d3c452edaf
SHA1: bb587d00287c13d9e4324bc76c13abbd493efa81
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.hibernate.core Medium
Vendor pom organization name Hibernate.org High
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom groupid org.hibernate Highest
Vendor pom name A Hibernate O/RM Module High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom groupid hibernate Highest
Vendor pom url http://hibernate.org Highest
Vendor pom organization url http://hibernate.org Medium
Vendor manifest Bundle-Description Hibernate ORM Core Medium
Vendor pom artifactid hibernate-core Low
Vendor central groupid org.hibernate Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor file name hibernate-core High
Product Manifest bundle-symbolicname org.hibernate.core Medium
Product pom description A module of the Hibernate O/RM project Medium
Product pom name A Hibernate O/RM Module High
Product pom artifactid hibernate-core Highest
Product pom organization name Hibernate.org Low
Product pom organization url http://hibernate.org Low
Product Manifest implementation-url http://hibernate.org Low
Product pom groupid hibernate Low
Product central artifactid hibernate-core Highest
Product manifest Bundle-Description Hibernate ORM Core Medium
Product Manifest Bundle-Name hibernate-core Medium
Product pom url http://hibernate.org Medium
Product file name hibernate-core High
Version file version 4.2.21 Highest
Version Manifest Implementation-Version 4.2.21.Final High
Version pom version 4.2.21.Final Highest
Version central version 4.2.21.Final Highest
exo.core.component.organization.api-6.0.x-SNAPSHOT.jar
Description: API of Organization Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.organization.api/6.0.x-SNAPSHOT/exo.core.component.organization.api-6.0.x-SNAPSHOT.jar
MD5: a7eb0f78ea4e73e5c8560e0697866970
SHA1: b5c9fa30c3833c3e0769a7bcf761c5366805a732
Referenced In Projects/Scopes:
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Commons Search:provided
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name exo.core.component.organization.api High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom artifactid exo.core.component.organization.api Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF Core :: Component :: Organization Service API High
Vendor pom groupid exoplatform.core Highest
Vendor pom groupid org.exoplatform.core Highest
Vendor pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom parent-artifactid core-parent Low
Product file name exo.core.component.organization.api High
Product Manifest specification-title exo-core Medium
Product pom artifactid exo.core.component.organization.api Highest
Product pom parent-artifactid core-parent Medium
Product pom groupid exoplatform.core Low
Product pom name eXo PLF Core :: Component :: Organization Service API High
Product pom parent-groupid org.exoplatform.core Low
Product pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest Implementation-Title eXo PLF Core :: Component :: Organization Service API High
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.organization.api:6.0.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:api-platform:core:6.0
Confidence :Low
suppress
commons-io-2.4.jar
Description:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-io/commons-io/2.4/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.apache.commons.io Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-io Highest
Vendor pom artifactid commons-io Low
Vendor manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor pom url http://commons.apache.org/io/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low
Vendor file name commons-io High
Vendor pom groupid commons-io Highest
Vendor pom name Commons IO High
Vendor Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Product Manifest bundle-symbolicname org.apache.commons.io Medium
Product pom artifactid commons-io Highest
Product manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product Manifest Bundle-Name Commons IO Medium
Product pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product central artifactid commons-io Highest
Product Manifest specification-title Commons IO Medium
Product pom url http://commons.apache.org/io/ Medium
Product Manifest Implementation-Title Commons IO High
Product pom parent-groupid org.apache.commons Low
Product Manifest bundle-docurl http://commons.apache.org/io/ Low
Product file name commons-io High
Product pom parent-artifactid commons-parent Medium
Product pom groupid commons-io Low
Product pom name Commons IO High
Product Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Version file version 2.4 Highest
Version central version 2.4 Highest
Version Manifest Implementation-Version 2.4 High
Version pom version 2.4 Highest
fontbox-1.8.14.jar
Description:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/fontbox/1.8.14/fontbox-1.8.14.jar
MD5: 901640f7e2bd12508ae4a7cccba3df79
SHA1: 9c7caec614a6a132bedc83f1d6d247bb96ca0df3
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Vendor pom artifactid fontbox Low
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor file name fontbox High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor pom url http://pdfbox.apache.org/ Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom groupid apache.pdfbox Highest
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor pom name Apache FontBox High
Product pom parent-artifactid pdfbox-parent Medium
Product pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Product pom url http://pdfbox.apache.org/ Medium
Product file name fontbox High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product central artifactid fontbox Highest
Product Manifest Bundle-Name Apache FontBox Medium
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest Implementation-Title Apache FontBox High
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom artifactid fontbox Highest
Product pom groupid apache.pdfbox Low
Product manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product Manifest specification-title Apache FontBox Medium
Product pom name Apache FontBox High
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
jempbox-1.8.14.jar
Description:
The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM)
specification. JempBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/jempbox/1.8.14/jempbox-1.8.14.jar
MD5: 393135759731daf4e301903b3de2fbbb
SHA1: 7f94c7cd4efc21e78729436cc4cf0c09eeea0f38
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom name Apache JempBox High
Vendor file name jempbox High
Vendor pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom groupid apache.pdfbox Highest
Vendor pom artifactid jempbox Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Product Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Product pom parent-artifactid pdfbox-parent Medium
Product pom name Apache JempBox High
Product file name jempbox High
Product pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom artifactid jempbox Highest
Product Manifest Bundle-Name Apache JempBox Medium
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product central artifactid jempbox Highest
Product Manifest Implementation-Title Apache JempBox High
Product pom groupid apache.pdfbox Low
Product manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product Manifest specification-title Apache JempBox Medium
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
pdfbox-1.8.14.jar
Description:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/pdfbox/1.8.14/pdfbox-1.8.14.jar
MD5: c90740e185fc2f8013d1119f509ea4f3
SHA1: 7550298240c8540b721733ede6dc88fcf4fa2b0f
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor file name pdfbox High
Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom artifactid pdfbox Low
Vendor manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Vendor pom groupid apache.pdfbox Highest
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom name Apache PDFBox High
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Product pom parent-artifactid pdfbox-parent Medium
Product file name pdfbox High
Product Manifest Implementation-Title Apache PDFBox High
Product Manifest specification-title Apache PDFBox Medium
Product Manifest bundle-symbolicname org.apache.pdfbox Medium
Product Manifest Bundle-Name Apache PDFBox Medium
Product pom artifactid pdfbox Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom name Apache PDFBox High
Product pom groupid apache.pdfbox Low
Product pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Product central artifactid pdfbox Highest
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
htmllexer-2.1.jar
Description: HTML Lexer is the low level lexical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmllexer/2.1/htmllexer-2.1.jar
MD5: 1cb7184766a0c52f4d98d671bb08be19
SHA1: 2ebf2c073e649b7e674cddd0558ff102a486402f
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid htmllexer Low
Vendor jar package name htmlparser Low
Vendor central groupid org.htmlparser Highest
Vendor pom name HTML Lexer Jar High
Vendor pom groupid org.htmlparser Highest
Vendor pom groupid htmlparser Highest
Vendor pom description HTML Lexer is the low level lexical analyzer. Medium
Vendor pom url http://htmlparser.org Highest
Vendor pom parent-groupid org.htmlparser Medium
Vendor file name htmllexer High
Vendor pom parent-artifactid HTMLParserProject Low
Product pom url http://htmlparser.org Medium
Product pom parent-groupid org.htmlparser Low
Product pom name HTML Lexer Jar High
Product pom groupid htmlparser Low
Product pom parent-artifactid HTMLParserProject Medium
Product central artifactid htmllexer Highest
Product pom description HTML Lexer is the low level lexical analyzer. Medium
Product pom artifactid htmllexer Highest
Product file name htmllexer High
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
htmlparser-2.1.jar
Description: HTML Parser is the high level syntactical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmlparser/2.1/htmlparser-2.1.jar
MD5: aa05b921026c228f92ef8b4a13c26f8d
SHA1: c752e5984b7767533cbd3fdffa48cecb52fa226c
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid htmlparser Low
Vendor file name htmlparser High
Vendor jar package name htmlparser Low
Vendor central groupid org.htmlparser Highest
Vendor pom description HTML Parser is the high level syntactical analyzer. Medium
Vendor pom name HTML Parser Jar High
Vendor pom groupid org.htmlparser Highest
Vendor pom groupid htmlparser Highest
Vendor pom url http://htmlparser.org Highest
Vendor pom parent-groupid org.htmlparser Medium
Vendor pom parent-artifactid HTMLParserProject Low
Product file name htmlparser High
Product pom description HTML Parser is the high level syntactical analyzer. Medium
Product pom url http://htmlparser.org Medium
Product pom parent-groupid org.htmlparser Low
Product pom artifactid htmlparser Highest
Product pom groupid htmlparser Low
Product pom name HTML Parser Jar High
Product pom parent-artifactid HTMLParserProject Medium
Product central artifactid htmlparser Highest
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
poi-3.13.jar
Description: Apache POI - Java API To Access Microsoft Format Files
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi/3.13/poi-3.13.jar
MD5: 1b43f32e2211546040597a9e2d07b869
SHA1: 0f59f504ba8c521e61e25f417ec652fd485010f3
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor pom organization name Apache Software Foundation High
Vendor central groupid org.apache.poi Highest
Vendor pom description Apache POI - Java API To Access Microsoft Format Files Medium
Vendor file name poi High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom name Apache POI High
Vendor pom artifactid poi Low
Vendor pom url http://poi.apache.org/ Highest
Vendor pom groupid org.apache.poi Highest
Vendor pom groupid apache.poi Highest
Product pom url http://poi.apache.org/ Medium
Product pom artifactid poi Highest
Product pom groupid apache.poi Low
Product Manifest Implementation-Title Apache POI High
Product pom organization url http://www.apache.org/ Low
Product pom description Apache POI - Java API To Access Microsoft Format Files Medium
Product central artifactid poi Highest
Product file name poi High
Product pom organization name Apache Software Foundation Low
Product pom name Apache POI High
Product Manifest specification-title Apache POI Medium
Version central version 3.13 Highest
Version file version 3.13 Highest
Version pom version 3.13 Highest
Version Manifest Implementation-Version 3.13 High
Related Dependencies
poi-ooxml-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml/3.13/poi-ooxml-3.13.jar
SHA1: c364a8f5422d613e3a56db3b4b889f2989d7ee73
MD5: 38bb36c35a16030d4bc0ac14421430d7
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml:3.13 ✓
poi-ooxml-schemas-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml-schemas/3.13/poi-ooxml-schemas-3.13.jar
SHA1: 56fb0b9f3ffc3d7f7fc9b59e17b5fa2c3ab921e7
MD5: ca12e13961e9df83ddd5471733d73d91
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml-schemas:3.13 ✓
poi-scratchpad-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-scratchpad/3.13/poi-scratchpad-3.13.jar
SHA1: 09d763275e6c7fa05d47e2581606748669e88c55
MD5: d8dbe05b289da779874e4783881e1b57
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-scratchpad:3.13 ✓
Published Vulnerabilities
CVE-2016-5000 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Vulnerable Software & Versions:
CVE-2017-5644 suppress
Severity:
High
CVSS Score: 7.1
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
CWE: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Vulnerable Software & Versions:
tika-core-1.5.jar
Description: This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-core/1.5/tika-core-1.5.jar
MD5: e864bf637f51283dc525087b015d7b1a
SHA1: 194ca0fb3d73b07737524806fbc3bec89063c03a
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.apache.tika Medium
Vendor pom organization name The Apache Software Foundation High
Vendor Manifest bundle-docurl http://tika.apache.org/ Low
Vendor pom name Apache Tika core High
Vendor pom parent-artifactid tika-parent Low
Vendor central groupid org.apache.tika Highest
Vendor pom groupid apache.tika Highest
Vendor pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor pom organization url http://www.apache.org Medium
Vendor pom url http://tika.apache.org/ Highest
Vendor file name tika-core High
Vendor pom groupid org.apache.tika Highest
Vendor manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor Manifest bundle-symbolicname org.apache.tika.core Medium
Vendor pom artifactid tika-core Low
Product pom parent-artifactid tika-parent Medium
Product pom artifactid tika-core Highest
Product Manifest bundle-docurl http://tika.apache.org/ Low
Product pom organization name The Apache Software Foundation Low
Product pom name Apache Tika core High
Product pom url http://tika.apache.org/ Medium
Product pom organization url http://www.apache.org Low
Product pom parent-groupid org.apache.tika Low
Product pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product file name tika-core High
Product pom groupid apache.tika Low
Product manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product Manifest bundle-symbolicname org.apache.tika.core Medium
Product central artifactid tika-core Highest
Product Manifest Bundle-Name Apache Tika core Medium
Version central version 1.5 Highest
Version file version 1.5 Highest
Version pom version 1.5 Highest
Related Dependencies
tika-parsers-1.5.jar
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-parsers/1.5/tika-parsers-1.5.jar
SHA1: 9b895231b7a0dae7349dfb42cb1b926c345b5281
MD5: f1056da5d1021ad1bbac7dab01b335d1
cpe: cpe:/a:apache:tika:1.5
maven: org.apache.tika:tika-parsers:1.5 ✓
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11762 suppress
Severity:
Medium
CVSS Score: 5.8
(AV:N/AC:M/Au:N/C:N/I:P/A:P)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-8017 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Vulnerable Software & Versions: (show all )
vorbis-java-core-0.1-tests.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1-tests.jar
MD5: d58f076c08a917277d03f3417aa867a6
SHA1: c849979e199d8a7c3da1a00799c623c00f94efac
Referenced In Projects/Scopes:
eXo PLF:: Commons - WebUI Extension:test,provided
eXo PLF:: Commons - Commons WebUI:test,provided
eXo PLF:: Commons - Testing:test,provided
eXo PLF:: Commons - Comet Services:test,provided
eXo PLF:: Commons - Transparent Upgrade Framework:test,provided
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:test,provided
eXo PLF:: Commons - Product Informations:test,provided
eXo PLF:: Commons - Juzu Bridge for Platform:test,provided
eXo PLF:: Commons - Comet Ext Service (test only):test,provided
eXo PLF:: Commons - Common Services:test,provided
Evidence
Type Source Name Value Confidence
Vendor jar package name gagravarr Low
Vendor jar package name ogg Low
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom groupid gagravarr Highest
Vendor pom name Ogg and Vorbis for Java, Core High
Vendor pom parent-groupid org.gagravarr Medium
Vendor central groupid org.gagravarr Highest
Vendor file name vorbis-java-core High
Vendor pom artifactid vorbis-java-core Low
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor pom groupid org.gagravarr Highest
Product jar package name ogg Low
Product central artifactid vorbis-java-core Highest
Product pom parent-artifactid vorbis-java-parent Medium
Product pom name Ogg and Vorbis for Java, Core High
Product pom groupid gagravarr Low
Product file name vorbis-java-core High
Product pom artifactid vorbis-java-core Highest
Product pom parent-groupid org.gagravarr Low
Product pom url Gagravarr/VorbisJava High
Version central version 0.1 Highest
Version pom version 0.1 Highest
Version file version 0.1 Highest
vorbis-java-tika-0.1.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-tika/0.1/vorbis-java-tika-0.1.jar
MD5: 1fccc6796a0924ba4f32eb1d44b8616b
SHA1: 6966c8663a7f689021accb13cceaa6101f53ea3d
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name gagravarr Low
Vendor file name vorbis-java-tika High
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom groupid gagravarr Highest
Vendor pom parent-groupid org.gagravarr Medium
Vendor pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Vendor central groupid org.gagravarr Highest
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor jar package name tika Low
Vendor pom groupid org.gagravarr Highest
Vendor pom artifactid vorbis-java-tika Low
Product file name vorbis-java-tika High
Product pom parent-artifactid vorbis-java-parent Medium
Product pom artifactid vorbis-java-tika Highest
Product pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Product pom groupid gagravarr Low
Product jar package name tika Low
Product pom parent-groupid org.gagravarr Low
Product pom url Gagravarr/VorbisJava High
Product central artifactid vorbis-java-tika Highest
Version central version 0.1 Highest
Version pom version 0.1 Highest
Version file version 0.1 Highest
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
netcdf-4.2-min.jar
Description: The NetCDF-Java Library is a Java interface to NetCDF files,
as well as to many other types of scientific data formats.
License:
(MIT-style) netCDF C library license.: http://www.unidata.ucar.edu/software/netcdf/copyright.html
File Path: /home/ciagent/.m2/repository/edu/ucar/netcdf/4.2-min/netcdf-4.2-min.jar
MD5: eb00b40b0511f0fc1dfcfc9cb89e3c53
SHA1: 0f3c3f3db4c54483aa1fbc4497e300879ce24da1
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Vendor pom groupid edu.ucar Highest
Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/ Highest
Vendor pom artifactid netcdf Low
Vendor Manifest built-on 2010-11-24 05:51:29 Low
Vendor pom name The NetCDF-Java Library High
Vendor central groupid edu.ucar Highest
Vendor Manifest Implementation-Vendor UCAR/Unidata High
Vendor file name netcdf High
Product Manifest Implementation-Title NetCDF-Java-Library High
Product pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Product central artifactid netcdf Highest
Product pom url http://www.unidata.ucar.edu/software/netcdf-java/ Medium
Product Manifest built-on 2010-11-24 05:51:29 Low
Product pom name The NetCDF-Java Library High
Product pom artifactid netcdf Highest
Product pom groupid edu.ucar Low
Product file name netcdf High
Version file version 4.2 Highest
Version pom version 4.2-min Highest
Version central version 4.2-min Highest
apache-mime4j-core-0.7.2.jar
Description: Java stream based MIME message parser
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-core/0.7.2/apache-mime4j-core-0.7.2.jar
MD5: 88f799546eca803c53eee01a4ce5edcd
SHA1: a81264fe0265ebe8fd1d8128aad06dc320de6eef
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid apache-mime4j-core Low
Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Vendor pom groupid org.apache.james Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom groupid apache.james Highest
Vendor file name apache-mime4j-core High
Vendor Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Vendor manifest Bundle-Description Java stream based MIME message parser Medium
Vendor Manifest bundle-docurl http://www.apache.org/ Low
Vendor pom parent-artifactid apache-mime4j-project Low
Vendor central groupid org.apache.james Highest
Vendor pom parent-groupid org.apache.james Medium
Vendor pom name Apache JAMES Mime4j (Core) High
Product pom artifactid apache-mime4j-core Highest
Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Product central artifactid apache-mime4j-core Highest
Product pom parent-artifactid apache-mime4j-project Medium
Product Manifest specification-title Apache Mime4j Medium
Product file name apache-mime4j-core High
Product Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Product pom groupid apache.james Low
Product Manifest Implementation-Title Apache Mime4j High
Product manifest Bundle-Description Java stream based MIME message parser Medium
Product Manifest bundle-docurl http://www.apache.org/ Low
Product Manifest Bundle-Name Apache JAMES Mime4j (Core) Medium
Product pom parent-groupid org.apache.james Low
Product pom name Apache JAMES Mime4j (Core) High
Version pom version 0.7.2 Highest
Version Manifest Implementation-Version 0.7.2 High
Version central version 0.7.2 Highest
Version file version 0.7.2 Highest
Related Dependencies
apache-mime4j-dom-0.7.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-dom/0.7.2/apache-mime4j-dom-0.7.2.jar
SHA1: 1c289aa264548a0a1f1b43685a9cb2ab23f67287
MD5: dedc747b5c367fbd7f8a7235d1d7cbee
maven: org.apache.james:apache-mime4j-dom:0.7.2 ✓
xz-1.2.jar
Description: XZ data compression
License:
Public Domain
File Path: /home/ciagent/.m2/repository/org/tukaani/xz/1.2/xz-1.2.jar
MD5: 04bd31459826c30c2a3c304e3b225ad4
SHA1: bfc66dda280a18ab341b5023248925265c00394c
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom description XZ data compression Medium
Vendor pom groupid org.tukaani Highest
Vendor pom url http://tukaani.org/xz/java.html Highest
Vendor Manifest bundle-symbolicname org.tukaani.xz Medium
Vendor pom artifactid xz Low
Vendor file name xz High
Vendor central groupid org.tukaani Highest
Vendor Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Vendor pom groupid tukaani Highest
Vendor pom name XZ for Java High
Vendor Manifest implementation-url http://tukaani.org/xz/java.html Low
Product pom description XZ data compression Medium
Product Manifest Implementation-Title XZ data compression High
Product pom url http://tukaani.org/xz/java.html Medium
Product pom groupid tukaani Low
Product file name xz High
Product Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Product Manifest implementation-url http://tukaani.org/xz/java.html Low
Product Manifest Bundle-Name XZ data compression Medium
Product Manifest bundle-symbolicname org.tukaani.xz Medium
Product central artifactid xz Highest
Product pom name XZ for Java High
Product pom artifactid xz Highest
Version Manifest Implementation-Version 1.2 High
Version pom version 1.2 Highest
Version file version 1.2 Highest
Version central version 1.2 Highest
maven: org.tukaani:xz:1.2 ✓
Confidence :Highest
cpe: cpe:/a:tukaani:xz:1.2
Confidence :Low
suppress
Published Vulnerabilities
CVE-2015-4035 suppress
Severity:
Medium
CVSS Score: 4.6
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
Vulnerable Software & Versions:
commons-compress-1.5.jar
Description:
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-compress/1.5/commons-compress-1.5.jar
MD5: 5e18cfcf472548c2e0b90a4ea1cedf42
SHA1: d2bd2c0bd328f1dabdf33e10b6d223ebcbe93343
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest extension-name org.apache.commons.compress Medium
Vendor Manifest bundle-symbolicname org.apache.commons.compress Medium
Vendor Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Vendor central groupid org.apache.commons Highest
Vendor manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor Manifest bundle-docurl http://commons.apache.org/compress/ Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor pom groupid org.apache.commons Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom name Commons Compress High
Vendor pom groupid apache.commons Highest
Vendor pom artifactid commons-compress Low
Vendor pom url http://commons.apache.org/compress/ Highest
Vendor file name commons-compress High
Product pom url http://commons.apache.org/compress/ Medium
Product Manifest Bundle-Name Commons Compress Medium
Product Manifest extension-name org.apache.commons.compress Medium
Product Manifest bundle-symbolicname org.apache.commons.compress Medium
Product Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Product Manifest specification-title Commons Compress Medium
Product Manifest Implementation-Title Commons Compress High
Product central artifactid commons-compress Highest
Product manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product pom artifactid commons-compress Highest
Product Manifest bundle-docurl http://commons.apache.org/compress/ Low
Product pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product pom name Commons Compress High
Product pom groupid apache.commons Low
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product file name commons-compress High
Version central version 1.5 Highest
Version file version 1.5 Highest
Version pom version 1.5 Highest
Version Manifest Implementation-Version 1.5 High
cpe: cpe:/a:apache:commons_compress:1.5
Confidence :Low
suppress
maven: org.apache.commons:commons-compress:1.5 ✓
Confidence :Highest
cpe: cpe:/a:apache:commons-compress:1.5
Confidence :Low
suppress
bcmail-jdk15-1.45.jar
Description: The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. If the S/MIME API is used, the JavaMail API and the Java activation framework will also be needed.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcmail-jdk15/1.45/bcmail-jdk15-1.45.jar
MD5: 13321fc7eff7bcada7b4fedfb592025c
SHA1: 3aed7e642dd8d39dc14ed1dec3ff79e084637148
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor pom name Bouncy Castle CMS and S/MIME API High
Vendor file name bcmail-jdk15 High
Vendor Manifest extension-name org.bouncycastle.bcmail Medium
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor central groupid org.bouncycastle Highest
Vendor pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Vendor pom artifactid bcmail-jdk15 Low
Vendor pom groupid bouncycastle Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor pom groupid org.bouncycastle Highest
Product central artifactid bcmail-jdk15 Highest
Product pom groupid bouncycastle Low
Product pom url http://www.bouncycastle.org/java.html Medium
Product pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Product pom artifactid bcmail-jdk15 Highest
Product pom name Bouncy Castle CMS and S/MIME API High
Product file name bcmail-jdk15 High
Product Manifest extension-name org.bouncycastle.bcmail Medium
Version central version 1.45 Highest
Version file version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version pom version 1.45 Highest
cpe: cpe:/a:no-cms_project:no-cms:1.45
Confidence :Low
suppress
cpe: cpe:/a:mime_project:mime:1.45
Confidence :Low
suppress
maven: org.bouncycastle:bcmail-jdk15:1.45 ✓
Confidence :Highest
bcprov-jdk15-1.45.jar
Description: The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcprov-jdk15/1.45/bcprov-jdk15-1.45.jar
MD5: 2062f8e3d15748443ea60a94b266371c
SHA1: 7741883cb07b4634e8b5fd3337113b6ea770a9bb
Referenced In Projects/Scopes:
eXo PLF:: Commons - Comet Services:compile
eXo PLF:: Commons - Testing:compile
eXo PLF:: Commons - WebUI Extension:compile
eXo PLF:: Commons - Transparent Upgrade Framework:compile
eXo PLF:: Commons - Product Informations:compile
eXo PLF:: Commons - Comet Ext Service (test only):compile
eXo PLF:: Commons - Juzu Bridge for Platform:compile
eXo PLF:: Commons - Commons WebUI:compile
eXo PLF:: Commons - Commons Extension Webapp:runtime
eXo PLF:: Commons - API:compile
eXo PLF:: Commons - Common Services:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid bcprov-jdk15 Low
Vendor pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor Manifest extension-name org.bouncycastle.bcprovider Medium
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor file name bcprov-jdk15 High
Vendor pom name Bouncy Castle Provider High
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor central groupid org.bouncycastle Highest
Vendor pom groupid bouncycastle Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor pom groupid org.bouncycastle Highest
Product pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Product pom groupid bouncycastle Low
Product Manifest extension-name org.bouncycastle.bcprovider Medium
Product pom url http://www.bouncycastle.org/java.html Medium
Product central artifactid bcprov-jdk15 Highest
Product pom artifactid bcprov-jdk15 Highest
Product file name bcprov-jdk15 High
Product pom name Bouncy Castle Provider High
Version central version 1.45 Highest
Version file version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version pom version 1.45 Highest
cpe: cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45
Confidence :Low