Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : May 26, 2019 at 07:54:43 +00:00
Dependencies Scanned : 133 (118 unique)
Vulnerable Dependencies : 20
Vulnerabilities Found : 40
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 16/05/2019 09:15:31
NVD CVE 2003 : 24/05/2019 08:15:38
NVD CVE 2004 : 16/05/2019 09:15:31
NVD CVE 2005 : 24/05/2019 08:15:38
NVD CVE 2006 : 23/05/2019 08:15:43
NVD CVE 2007 : 25/05/2019 08:15:38
NVD CVE 2008 : 25/05/2019 08:15:38
NVD CVE 2009 : 24/05/2019 08:15:38
NVD CVE 2010 : 24/05/2019 08:15:38
NVD CVE 2011 : 23/05/2019 08:15:44
NVD CVE 2012 : 25/05/2019 08:15:39
NVD CVE 2013 : 25/05/2019 08:15:39
NVD CVE 2014 : 25/05/2019 08:15:39
NVD CVE 2015 : 25/05/2019 07:45:46
NVD CVE 2016 : 25/05/2019 07:45:46
NVD CVE 2017 : 25/05/2019 07:45:47
NVD CVE 2018 : 25/05/2019 07:45:47
NVD CVE 2019 : 26/05/2019 07:15:28
NVD CVE Checked : 26/05/2019 07:38:11
NVD CVE Modified : 26/05/2019 05:15:29
VersionCheckOn : 1558856291461
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor pom groupid javax.jcr Highest
Vendor file name jcr High
Vendor pom name Content Repository for Java Technology API High
Vendor Manifest extension-name jcr Medium
Vendor pom artifactid jcr Low
Vendor pom organization name Day Software Management AG High
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor Manifest Implementation-Vendor Day Software Management AG High
Vendor pom organization url http://www.day.com/ Medium
Product Manifest Implementation-Title javax.jcr High
Product file name jcr High
Product pom groupid javax.jcr Low
Product pom artifactid jcr Highest
Product pom name Content Repository for Java Technology API High
Product Manifest extension-name jcr Medium
Product pom organization name Day Software Management AG Low
Product Manifest specification-title Content Repository for Java Technology API Medium
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product pom organization url http://www.day.com/ Low
Version file version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
Version pom version 1.0.1 Highest
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor Manifest extension-name javax.ws.rs Medium
Vendor pom organization name Sun Microsystems, Inc High
Vendor pom artifactid jsr311-api Low
Vendor pom name jsr311-api High
Vendor pom groupid javax.ws.rs Highest
Vendor central groupid javax.ws.rs Highest
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor pom organization url http://www.sun.com/ Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor file name jsr311-api High
Vendor pom url https://jsr311.dev.java.net Highest
Product Manifest bundle-docurl http://www.sun.com/ Low
Product Manifest extension-name javax.ws.rs Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product central artifactid jsr311-api Highest
Product Manifest Bundle-Name jsr311-api Medium
Product pom name jsr311-api High
Product pom artifactid jsr311-api Highest
Product pom groupid javax.ws.rs Low
Product pom organization name Sun Microsystems, Inc Low
Product pom url https://jsr311.dev.java.net Medium
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Product pom organization url http://www.sun.com/ Low
Product file name jsr311-api High
Version central version 1.1.1 Highest
Version file version 1.1.1 Highest
Version pom version 1.1.1 Highest
hamcrest-core-1.3.jar
Description:
This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations.
File Path: /home/ciagent/.m2/repository/org/hamcrest/hamcrest-core/1.3/hamcrest-core-1.3.jar
MD5: 6393363b47ddcbba82321110c3e07519
SHA1: 42a25dc3219429f0e5d060061f71acb49bf010a0
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid hamcrest-core Low
Vendor pom description This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations. Low
Vendor pom groupid org.hamcrest Highest
Vendor pom name Hamcrest Core High
Vendor pom parent-groupid org.hamcrest Medium
Vendor central groupid org.hamcrest Highest
Vendor pom groupid hamcrest Highest
Vendor Manifest Implementation-Vendor hamcrest.org High
Vendor file name hamcrest-core High
Vendor Manifest built-date 2012-07-09 19:49:34 Low
Vendor pom parent-artifactid hamcrest-parent Low
Product pom description This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations. Low
Product pom name Hamcrest Core High
Product pom parent-groupid org.hamcrest Low
Product pom parent-artifactid hamcrest-parent Medium
Product central artifactid hamcrest-core Highest
Product file name hamcrest-core High
Product Manifest Implementation-Title hamcrest-core High
Product Manifest built-date 2012-07-09 19:49:34 Low
Product pom artifactid hamcrest-core Highest
Product pom groupid hamcrest Low
Version file version 1.3 Highest
Version central version 1.3 Highest
Version Manifest Implementation-Version 1.3 High
Version pom version 1.3 Highest
junit-4.12.jar
Description: JUnit is a unit testing framework for Java, created by Erich Gamma and Kent Beck.
License:
Eclipse Public License 1.0: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/ciagent/.m2/repository/junit/junit/4.12/junit-4.12.jar
MD5: 5b38c40c97fbd0adee29f91e60405584
SHA1: 2973d150c0dc1fefe998f834810d68f278ea58ec
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name junit High
Vendor pom organization url http://www.junit.org Medium
Vendor pom description JUnit is a unit testing framework for Java, created by Erich Gamma and Kent Beck. Medium
Vendor pom url http://junit.org Highest
Vendor central groupid junit Highest
Vendor Manifest Implementation-Vendor-Id junit Medium
Vendor pom artifactid junit Low
Vendor Manifest Implementation-Vendor JUnit High
Vendor pom name JUnit High
Vendor pom organization name JUnit High
Vendor pom groupid junit Highest
Product file name junit High
Product pom description JUnit is a unit testing framework for Java, created by Erich Gamma and Kent Beck. Medium
Product central artifactid junit Highest
Product Manifest Implementation-Title JUnit High
Product pom organization name JUnit Low
Product pom groupid junit Low
Product pom artifactid junit Highest
Product pom name JUnit High
Product pom organization url http://www.junit.org Low
Product pom url http://junit.org Medium
Version file version 4.12 Highest
Version central version 4.12 Highest
Version Manifest Implementation-Version 4.12 High
Version pom version 4.12 Highest
portlet-api-2.0.jar
Description: The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group.
File Path: /home/ciagent/.m2/repository/javax/portlet/portlet-api/2.0/portlet-api-2.0.jar
MD5: 0ec08593cda1df33985391919996c740
SHA1: 1cd72f2a37fcf8ab9893a9468d7ba71c85fe2653
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.jcp.org/en/jsr/detail?id=286 Highest
Vendor Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Vendor pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Vendor pom groupid javax.portlet Highest
Vendor pom name Java Portlet Specification V2.0 High
Vendor file name portlet-api High
Vendor pom artifactid portlet-api Low
Vendor central groupid javax.portlet Highest
Vendor Manifest bundle-symbolicname javax.portlet Medium
Product pom groupid javax.portlet Low
Product central artifactid portlet-api Highest
Product Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Product pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Product pom name Java Portlet Specification V2.0 High
Product file name portlet-api High
Product pom url http://www.jcp.org/en/jsr/detail?id=286 Medium
Product Manifest Bundle-Name JSR 286 Medium
Product pom artifactid portlet-api Highest
Product Manifest bundle-symbolicname javax.portlet Medium
Version pom version 2.0 Highest
Version file version 2.0 Highest
Version central version 2.0 Highest
jsf-api-1.2_13.jar
Description: This is the master POM file for Sun's Implementation of
the JSF 1.2 Specification.
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/faces/jsf-api/1.2_13/jsf-api-1.2_13.jar
MD5: f8134eb324cb36b7518e9d613123ba84
SHA1: 56d9b9a374c19f0c636b40611a2af8eb020e8349
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization name Sun Microsystems, Inc High
Vendor manifest Bundle-Description Mojarra JSF API (javax.faces/1.2MR2) 1.2_13-b01-FCS Medium
Vendor Manifest today July 2 2009 Low
Vendor Manifest docname JavaServer Faces API Medium
Vendor central groupid javax.faces Highest
Vendor pom artifactid jsf-api Low
Vendor pom url http://java.sun.com/javaee/javaserverfaces/ Highest
Vendor Manifest extension-name javax.faces Medium
Vendor pom description This is the master POM file for Sun's Implementation of
the JSF 1.2 Specification. Medium
Vendor pom organization url http://www.sun.com/ Medium
Vendor Manifest dstamp 20090702 Low
Vendor Manifest tstamp 1551 Low
Vendor pom groupid javax.faces Highest
Vendor file name jsf-api High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor Manifest bundle-symbolicname javax.faces.jsf-api Medium
Product pom artifactid jsf-api Highest
Product pom groupid javax.faces Low
Product manifest Bundle-Description Mojarra JSF API (javax.faces/1.2MR2) 1.2_13-b01-FCS Medium
Product Manifest today July 2 2009 Low
Product Manifest docname JavaServer Faces API Medium
Product Manifest specification-title JavaServer Faces Medium
Product pom url http://java.sun.com/javaee/javaserverfaces/ Medium
Product central artifactid jsf-api Highest
Product Manifest Bundle-Name Mojarra JSF API Implementation 1.2_13-b01-FCS Medium
Product Manifest extension-name javax.faces Medium
Product Manifest Implementation-Title Mojarra High
Product pom description This is the master POM file for Sun's Implementation of
the JSF 1.2 Specification. Medium
Product pom organization name Sun Microsystems, Inc Low
Product pom organization url http://www.sun.com/ Low
Product Manifest dstamp 20090702 Low
Product Manifest tstamp 1551 Low
Product file name jsf-api High
Product Manifest bundle-symbolicname javax.faces.jsf-api Medium
Version file version 1.2.13 Highest
Version pom version 1.2_13 Highest
Version central version 1.2_13 Highest
exo.tool.framework.junit-1.2.4-GA.jar
Description: eXo Mock Objects framework
File Path: /home/ciagent/.m2/repository/org/exoplatform/tool/exo.tool.framework.junit/1.2.4-GA/exo.tool.framework.junit-1.2.4-GA.jar
MD5: 234e9a04ae75cb288ecf2a2d0541c5ed
SHA1: 70f6928cb4fae46c817e18509f66fce57e74f181
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest implementation-url http://www.jboss.org/foundation-parent/exo.tool.framework.junit Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.tool Medium
Vendor pom parent-artifactid foundation-parent Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid org.exoplatform.tool Highest
Vendor pom groupid exoplatform.tool Highest
Vendor pom artifactid exo.tool.framework.junit Low
Vendor pom name eXo Mock Objects framework High
Vendor pom description eXo Mock Objects framework Medium
Vendor pom parent-groupid org.exoplatform Medium
Vendor file name exo.tool.framework.junit High
Product pom parent-groupid org.exoplatform Low
Product pom groupid exoplatform.tool Low
Product pom name eXo Mock Objects framework High
Product pom artifactid exo.tool.framework.junit Highest
Product pom description eXo Mock Objects framework Medium
Product Manifest Implementation-Title eXo Mock Objects framework High
Product Manifest implementation-url http://www.jboss.org/foundation-parent/exo.tool.framework.junit Low
Product Manifest specification-title exo-mock-objects Medium
Product file name exo.tool.framework.junit High
Product pom parent-artifactid foundation-parent Medium
Version pom version 1.2.4-GA Highest
Version Manifest Implementation-Version 1.2.4-GA High
Version file version 1.2.4 Highest
maven: org.exoplatform.tool:exo.tool.framework.junit:1.2.4-GA
Confidence :High
staxnav.core-0.9.8.jar
File Path: /home/ciagent/.m2/repository/org/staxnav/staxnav.core/0.9.8/staxnav.core-0.9.8.jar
MD5: 0f786e5be21df9fbe8753175564564c7
SHA1: 27bd12d4d74b0851e38de79f8299462d93ba3d7f
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid staxnav Highest
Vendor pom artifactid staxnav.core Low
Vendor pom parent-artifactid staxnav.parent Low
Vendor pom parent-groupid org.staxnav Medium
Vendor jar package name staxnav Low
Vendor central groupid org.staxnav Highest
Vendor file name staxnav.core High
Vendor pom groupid org.staxnav Highest
Vendor pom name Staxnav - Core High
Product pom groupid staxnav Low
Product pom artifactid staxnav.core Highest
Product file name staxnav.core High
Product central artifactid staxnav.core Highest
Product pom parent-artifactid staxnav.parent Medium
Product pom name Staxnav - Core High
Product pom parent-groupid org.staxnav Low
Version central version 0.9.8 Highest
Version file version 0.9.8 Highest
Version pom version 0.9.8 Highest
groovy-all-2.4.12.jar
Description: Groovy: A powerful, dynamic language for the JVM
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/codehaus/groovy/groovy-all/2.4.12/groovy-all-2.4.12.jar
MD5: dddb0b3d3619875fa1c538c743ae8f99
SHA1: 760afc568cbd94c09d78f801ce51aed1326710af
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Groovy: A powerful, dynamic language for the JVM Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid codehaus.groovy Highest
Vendor pom name Apache Groovy High
Vendor Manifest extension-name groovy Medium
Vendor pom organization url http://groovy-lang.org Medium
Vendor pom groupid org.codehaus.groovy Highest
Vendor Manifest bundle-symbolicname groovy-all Medium
Vendor file name groovy-all High
Vendor pom url http://groovy-lang.org Highest
Vendor manifest Bundle-Description Groovy Runtime Medium
Vendor Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Vendor pom organization name Apache Software Foundation High
Vendor central groupid org.codehaus.groovy Highest
Vendor pom artifactid groovy-all Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom description Groovy: A powerful, dynamic language for the JVM Medium
Product Manifest Bundle-Name Groovy Runtime Medium
Product pom artifactid groovy-all Highest
Product central artifactid groovy-all Highest
Product Manifest specification-title Groovy: a powerful, dynamic language for the JVM Medium
Product pom name Apache Groovy High
Product Manifest extension-name groovy Medium
Product pom organization name Apache Software Foundation Low
Product Manifest bundle-symbolicname groovy-all Medium
Product pom url http://groovy-lang.org Medium
Product Manifest Implementation-Title Groovy: a powerful, dynamic language for the JVM High
Product file name groovy-all High
Product manifest Bundle-Description Groovy Runtime Medium
Product Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Product pom organization url http://groovy-lang.org Low
Product pom groupid codehaus.groovy Low
Version Manifest Implementation-Version 2.4.12 High
Version file version 2.4.12 Highest
Version central version 2.4.12 Highest
Version pom version 2.4.12 Highest
closure-compiler-externs-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler-externs/v20170910/closure-compiler-externs-v20170910.jar
MD5: 573e49fb83760d25b675028eb612e2b2
SHA1: 036e801a929fcd121d212093923daf34986f5572
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Closure Compiler Externs High
Vendor pom groupid com.google.javascript Highest
Vendor file name closure-compiler-externs-v20170910 High
Vendor pom groupid google.javascript Highest
Vendor pom parent-groupid com.google.javascript Medium
Vendor central groupid com.google.javascript Highest
Vendor pom parent-artifactid closure-compiler-parent Low
Vendor pom artifactid closure-compiler-externs Low
Product pom name Closure Compiler Externs High
Product pom artifactid closure-compiler-externs Highest
Product file name closure-compiler-externs-v20170910 High
Product pom parent-groupid com.google.javascript Low
Product central artifactid closure-compiler-externs Highest
Product pom parent-artifactid closure-compiler-parent Medium
Product pom groupid google.javascript Low
Version central version v20170910 Highest
Version file name closure-compiler-externs-v20170910 Medium
Version pom version v20170910 Highest
Version file version 20170910 Medium
args4j-2.33.jar
Description: args4j : Java command line arguments parser
License:
http://www.opensource.org/licenses/mit-license.php
File Path: /home/ciagent/.m2/repository/args4j/args4j/2.33/args4j-2.33.jar
MD5: 0a6d515f76b15d29e3cd529de9319739
SHA1: bd87a75374a6d6523de82fef51fc3cfe9baf9fc9
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.kohsuke.org/ Low
Vendor file name args4j High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor central groupid args4j Highest
Vendor manifest Bundle-Description args4j : Java command line arguments parser Medium
Vendor pom name args4j High
Vendor Manifest bundle-symbolicname org.kohsuke.args4j Medium
Vendor pom groupid args4j Highest
Vendor pom artifactid args4j Low
Vendor pom parent-artifactid args4j-site Low
Product Manifest bundle-docurl http://www.kohsuke.org/ Low
Product file name args4j High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product manifest Bundle-Description args4j : Java command line arguments parser Medium
Product pom groupid args4j Low
Product pom artifactid args4j Highest
Product pom name args4j High
Product Manifest bundle-symbolicname org.kohsuke.args4j Medium
Product central artifactid args4j Highest
Product pom parent-artifactid args4j-site Medium
Product Manifest Bundle-Name args4j Medium
Version file version 2.33 Highest
Version central version 2.33 Highest
Version pom version 2.33 Highest
error_prone_annotations-2.0.18.jar
File Path: /home/ciagent/.m2/repository/com/google/errorprone/error_prone_annotations/2.0.18/error_prone_annotations-2.0.18.jar
MD5: 98051758c08c9b7111b3268655069432
SHA1: 5f65affce1684999e2f4024983835efc3504012e
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name google Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom groupid google.errorprone Highest
Vendor pom parent-groupid com.google.errorprone Medium
Vendor jar package name annotations Low
Vendor pom artifactid error_prone_annotations Low
Vendor jar package name errorprone Low
Vendor pom parent-artifactid error_prone_parent Low
Vendor central groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Product file name error_prone_annotations High
Product central artifactid error_prone_annotations Highest
Product pom parent-groupid com.google.errorprone Low
Product pom parent-artifactid error_prone_parent Medium
Product pom groupid google.errorprone Low
Product jar package name annotations Low
Product jar package name errorprone Low
Product pom artifactid error_prone_annotations Highest
Product pom name error-prone annotations High
Version file version 2.0.18 Highest
Version central version 2.0.18 Highest
Version pom version 2.0.18 Highest
gson-2.7.jar
Description: Gson JSON library
File Path: /home/ciagent/.m2/repository/com/google/code/gson/gson/2.7/gson-2.7.jar
MD5: 5134a2350f58890ffb9db0b40047195d
SHA1: 751f548c85fa49f330cecbb1875893f971b33c4e
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname com.google.gson Medium
Vendor file name gson High
Vendor manifest Bundle-Description Gson JSON library Medium
Vendor central groupid com.google.code.gson High
Vendor pom groupid google.code.gson Highest
Vendor pom name Gson High
Vendor pom artifactid gson Low
Vendor central groupid org.netbeans.external High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor Manifest bundle-contactaddress https://github.com/google/gson Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Vendor pom parent-groupid com.google.code.gson Medium
Vendor pom groupid com.google.code.gson Highest
Vendor pom parent-artifactid gson-parent Low
Product Manifest bundle-symbolicname com.google.gson Medium
Product central artifactid com-google-gson High
Product file name gson High
Product manifest Bundle-Description Gson JSON library Medium
Product pom parent-artifactid gson-parent Medium
Product pom parent-groupid com.google.code.gson Low
Product pom name Gson High
Product Manifest Bundle-Name Gson Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest bundle-contactaddress https://github.com/google/gson Low
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Product pom artifactid gson Highest
Product pom groupid google.code.gson Low
Product central artifactid gson High
Version central version RELEASE110 High
Version central version RELEASE100 High
Version central version 2.7 High
Version pom version 2.7 Highest
Version file version 2.7 Highest
jsinterop-annotations-1.0.0.jar
File Path: /home/ciagent/.m2/repository/com/google/jsinterop/jsinterop-annotations/1.0.0/jsinterop-annotations-1.0.0.jar
MD5: 93302e3d0cc146097ecd08039dc1de52
SHA1: 23c3a3c060ffe4817e67673cc8294e154b0a4a95
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jsinterop-annotations Low
Vendor jar package name annotations Low
Vendor central groupid com.google.jsinterop Highest
Vendor file name jsinterop-annotations High
Vendor pom groupid google.jsinterop Highest
Vendor pom parent-artifactid jsinterop Low
Vendor jar package name jsinterop Low
Vendor pom parent-groupid com.google.jsinterop Medium
Vendor pom groupid com.google.jsinterop Highest
Product pom parent-artifactid jsinterop Medium
Product jar package name annotations Low
Product pom groupid google.jsinterop Low
Product central artifactid jsinterop-annotations Highest
Product file name jsinterop-annotations High
Product pom parent-groupid com.google.jsinterop Low
Product pom artifactid jsinterop-annotations Highest
Version pom version 1.0.0 Highest
Version file version 1.0.0 Highest
Version central version 1.0.0 Highest
closure-compiler-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar
MD5: ca8e9f88ba9aad9c5e2c0f8f937fe869
SHA1: 3b87499e9ed3f068e69889182ab95cff92de0932
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name google Low
Vendor pom groupid com.google.javascript Highest
Vendor central groupid com.google.javascript Highest
Vendor file name closure-compiler-v20170910 High
Vendor jar package name javascript Low
Product central artifactid closure-compiler Highest
Product file name closure-compiler-v20170910 High
Product pom artifactid closure-compiler Highest
Product jar package name javascript Low
Version central version v20170910 Highest
Version pom version v20170910 Highest
Version file name closure-compiler-v20170910 Medium
Version file version 20170910 Medium
exo.portal.webui.framework-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.framework/5.3.x-SNAPSHOT/exo.portal.webui.framework-5.3.x-SNAPSHOT.jar
MD5: ac6505c0b91c838e9d5608a3a21349a3
SHA1: ef9436758e0044f245e0fa6b6b7c379ab286c52d
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.gatein.portal Highest
Vendor pom groupid exoplatform.gatein.portal Highest
Vendor Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Vendor pom artifactid exo.portal.webui.framework Low
Vendor pom name GateIn Portal WebUI Framework High
Vendor Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.framework/ Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.portal Medium
Vendor pom parent-artifactid exo.portal.webui Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor file name exo.portal.webui.framework High
Vendor pom parent-groupid org.exoplatform.gatein.portal Medium
Vendor Manifest os-name Linux Medium
Product Manifest specification-title GateIn Portal WebUI Framework Medium
Product pom parent-groupid org.exoplatform.gatein.portal Low
Product pom parent-artifactid exo.portal.webui Medium
Product pom name GateIn Portal WebUI Framework High
Product Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.framework/ Low
Product pom artifactid exo.portal.webui.framework Highest
Product pom groupid exoplatform.gatein.portal Low
Product file name exo.portal.webui.framework High
Product Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Product Manifest Implementation-Title GateIn Portal WebUI Framework High
Product Manifest os-name Linux Medium
Version pom version 5.3.x-20190524.094017-23 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.portal.component.web.resources-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.resources/5.3.x-SNAPSHOT/exo.portal.component.web.resources-5.3.x-SNAPSHOT.jar
SHA1: 4c7c2c7c8a9ef857c5e6795726325b48221a7208
MD5: c26f1dd1af02de020041a91458e46a1b
exo.portal.component.web.controller-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.controller/5.3.x-SNAPSHOT/exo.portal.component.web.controller-5.3.x-SNAPSHOT.jar
SHA1: 3a4bd38a13733428585e9a0d912b575bb0171065
MD5: 6c1694454dfac1798e4a0c331488ef46
maven: org.exoplatform.gatein.portal:exo.portal.webui.framework:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:in-portal:in-portal:5.3.20190524
Confidence :Low
suppress
jboss-logging-3.3.0.Final.jar
Description: The JBoss Logging Framework
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging/3.3.0.Final/jboss-logging-3.3.0.Final.jar
MD5: bc11af4b8ce7138cdc79b7ba8561638c
SHA1: 3616bb87707910296e2c195dc016287080bba5af
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.jboss.logging Highest
Vendor Manifest implementation-url http://www.jboss.org Low
Vendor pom artifactid jboss-logging Low
Vendor central groupid org.jboss.logging Highest
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom description The JBoss Logging Framework Medium
Vendor pom parent-artifactid jboss-parent Low
Vendor pom url http://www.jboss.org Highest
Vendor pom groupid jboss.logging Highest
Vendor file name jboss-logging High
Vendor pom parent-groupid org.jboss Medium
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor manifest Bundle-Description The JBoss Logging Framework Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom name JBoss Logging 3 High
Vendor Manifest os-name Linux Medium
Product pom url http://www.jboss.org Medium
Product Manifest implementation-url http://www.jboss.org Low
Product Manifest specification-title JBoss Logging 3 Medium
Product Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Product central artifactid jboss-logging Highest
Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Product pom groupid jboss.logging Low
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product pom description The JBoss Logging Framework Medium
Product pom parent-groupid org.jboss Low
Product file name jboss-logging High
Product pom parent-artifactid jboss-parent Medium
Product Manifest bundle-docurl http://www.jboss.org Low
Product manifest Bundle-Description The JBoss Logging Framework Medium
Product Manifest Bundle-Name JBoss Logging 3 Medium
Product Manifest Implementation-Title JBoss Logging 3 High
Product pom name JBoss Logging 3 High
Product pom artifactid jboss-logging Highest
Product Manifest os-name Linux Medium
Version Manifest Implementation-Version 3.3.0.Final High
Version central version 3.3.0.Final Highest
Version file version 3.3.0 Highest
Version pom version 3.3.0.Final Highest
xmlpull-1.1.3.1.jar
License:
Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt
File Path: /home/ciagent/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid xmlpull Low
Vendor jar package name v1 Low
Vendor jar package name xmlpull Low
Vendor central groupid xmlpull Highest
Vendor pom url http://www.xmlpull.org Highest
Vendor pom name XML Pull Parsing API High
Vendor pom groupid xmlpull Highest
Vendor file name xmlpull High
Product pom artifactid xmlpull Highest
Product pom url http://www.xmlpull.org Medium
Product pom groupid xmlpull Low
Product jar package name v1 Low
Product pom name XML Pull Parsing API High
Product central artifactid xmlpull Highest
Product file name xmlpull High
Version file version 1.1.3.1 Highest
Version pom version 1.1.3.1 Highest
Version central version 1.1.3.1 Highest
xpp3_min-1.1.4c.jar
Description: MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs such as Hotspot in JDK 1.4+.
License:
Indiana University Extreme! Lab Software License, vesion 1.1.1: http://www.extreme.indiana.edu/viewcvs/~checkout~/XPP3/java/LICENSE.txt
Public Domain: http://creativecommons.org/licenses/publicdomain
File Path: /home/ciagent/.m2/repository/xpp3/xpp3_min/1.1.4c/xpp3_min-1.1.4c.jar
MD5: dcd95bcb84b09897b2b66d4684c040da
SHA1: 19d4e90b43059058f6e056f794f0ea4030d60b86
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid xpp3 Highest
Vendor pom organization name Extreme! Lab, Indiana University High
Vendor jar package name v1 Low
Vendor jar package name xmlpull Low
Vendor pom artifactid xpp3_min Low
Vendor file name xpp3_min High
Vendor pom groupid xpp3 Highest
Vendor pom organization url http://www.extreme.indiana.edu/ Medium
Vendor pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Vendor pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Vendor pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Highest
Product jar package name v1 Low
Product pom organization url http://www.extreme.indiana.edu/ Low
Product pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Medium
Product file name xpp3_min High
Product central artifactid xpp3_min Highest
Product pom groupid xpp3 Low
Product pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Product pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Product pom artifactid xpp3_min Highest
Product pom organization name Extreme! Lab, Indiana University Low
Version pom version 1.1.4c Highest
Version central version 1.1.4c Highest
Version file version 1.1.4c Highest
xstream-1.4.10.jar
Description: XStream is a serialization library from Java objects to XML and back.
License:
http://x-stream.github.io/license.html
File Path: /home/ciagent/.m2/repository/com/thoughtworks/xstream/xstream/1.4.10/xstream-1.4.10.jar
MD5: d00eec778910f95b26201395ac64cca0
SHA1: dfecae23647abc9d9fd0416629a4213a3882b101
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest x-build-time 2017-05-23T14:28:02Z Low
Vendor manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Vendor file name xstream High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Vendor Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Vendor Manifest Implementation-Vendor XStream High
Vendor pom name XStream Core High
Vendor pom parent-artifactid xstream-parent Low
Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Vendor Manifest bundle-docurl http://x-stream.github.io Low
Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Vendor Manifest x-builder Maven 3.3.9 Low
Vendor pom groupid com.thoughtworks.xstream Highest
Vendor Manifest specification-vendor XStream Low
Vendor pom groupid thoughtworks.xstream Highest
Vendor pom artifactid xstream Low
Vendor central groupid com.thoughtworks.xstream Highest
Vendor Manifest Implementation-Vendor-Id com.thoughtworks.xstream Medium
Vendor Manifest bundle-symbolicname xstream Medium
Vendor Manifest x-compile-target 1.5 Low
Vendor pom parent-groupid com.thoughtworks.xstream Medium
Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Vendor Manifest x-compile-source 1.5 Low
Product Manifest Implementation-Title XStream Core High
Product central artifactid xstream Highest
Product pom artifactid xstream Highest
Product Manifest x-build-time 2017-05-23T14:28:02Z Low
Product manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Product file name xstream High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Product Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Product pom parent-groupid com.thoughtworks.xstream Low
Product Manifest Bundle-Name XStream Core Medium
Product pom name XStream Core High
Product pom groupid thoughtworks.xstream Low
Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Product Manifest bundle-docurl http://x-stream.github.io Low
Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Product Manifest x-builder Maven 3.3.9 Low
Product pom parent-artifactid xstream-parent Medium
Product Manifest specification-title XStream Core Medium
Product Manifest bundle-symbolicname xstream Medium
Product Manifest x-compile-target 1.5 Low
Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Product Manifest x-compile-source 1.5 Low
Version pom version 1.4.10 Highest
Version file version 1.4.10 Highest
Version central version 1.4.10 Highest
Version Manifest Implementation-Version 1.4.10 High
Published Vulnerabilities
CVE-2013-7285 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Vulnerable Software & Versions: (show all )
commons-testing-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-testing/5.3.x-SNAPSHOT/commons-testing-5.3.x-SNAPSHOT.jar
MD5: 72f6ec173cc5382beec30940007e5a82
SHA1: 65d5772e16c75aefdf0321cff5015ba4cc74a296
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom artifactid commons-testing Low
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid commons Low
Vendor pom name eXo PLF:: Commons - Testing High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid org.exoplatform.commons Highest
Vendor pom groupid exoplatform.commons Highest
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-testing Low
Vendor file name commons-testing High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Product Manifest Implementation-Title eXo PLF:: Commons - Testing High
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest specification-title eXo PLF:: Commons - Testing Medium
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-testing Low
Product file name commons-testing High
Product pom name eXo PLF:: Commons - Testing High
Product pom artifactid commons-testing Highest
Product pom groupid exoplatform.commons Low
Version pom version 5.3.x-20190524.100445-53 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-testing:5.3.x-SNAPSHOT
Confidence :High
exo.kernel.component.cache-5.3.x-SNAPSHOT.jar
Description: Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.cache/5.3.x-SNAPSHOT/exo.kernel.component.cache-5.3.x-SNAPSHOT.jar
MD5: 6a322bdcc585dcf7bb26e4b7554adf3c
SHA1: 249eab6c763268ea4c6bcc15a6b53bf38c49fb6e
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.kernel.component.cache High
Vendor pom name eXo PLF:: Kernel :: Component :: Cache Service High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.cache Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom groupid org.exoplatform.kernel Highest
Vendor pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Product file name exo.kernel.component.cache High
Product pom name eXo PLF:: Kernel :: Component :: Cache Service High
Product Manifest specification-title exo-kernel Medium
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Cache Service High
Product pom parent-groupid org.exoplatform.kernel Low
Product pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom artifactid exo.kernel.component.cache Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.cache:5.3.x-SNAPSHOT
Confidence :High
antlr-2.7.7.jar
Description:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html
File Path: /home/ciagent/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid antlr Highest
Vendor jar package name antlr Low
Vendor central groupid antlr Highest
Vendor pom name AntLR Parser Generator High
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor pom artifactid antlr Low
Vendor file name antlr High
Vendor pom url http://www.antlr.org/ Highest
Product pom url http://www.antlr.org/ Medium
Product pom artifactid antlr Highest
Product pom name AntLR Parser Generator High
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom groupid antlr Low
Product central artifactid antlr Highest
Product file name antlr High
Version central version 2.7.7 Highest
Version file version 2.7.7 Highest
Version pom version 2.7.7 Highest
dom4j-1.6.1.jar
Description: dom4j: the flexible XML framework for Java
File Path: /home/ciagent/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid dom4j Low
Vendor pom description dom4j: the flexible XML framework for Java Medium
Vendor Manifest specification-vendor MetaStuff Ltd. Low
Vendor Manifest extension-name dom4j Medium
Vendor central groupid dom4j High
Vendor pom name dom4j High
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom organization url http://sourceforge.net/projects/dom4j Medium
Vendor file name dom4j High
Vendor pom groupid dom4j Highest
Vendor pom url http://dom4j.org Highest
Vendor pom organization name MetaStuff Ltd. High
Vendor Manifest Implementation-Vendor MetaStuff Ltd. High
Product pom description dom4j: the flexible XML framework for Java Medium
Product pom organization name MetaStuff Ltd. Low
Product pom url http://dom4j.org Medium
Product Manifest extension-name dom4j Medium
Product Manifest specification-title dom4j : XML framework for Java Medium
Product pom name dom4j High
Product pom organization url http://sourceforge.net/projects/dom4j Low
Product pom artifactid dom4j Highest
Product Manifest Implementation-Title org.dom4j High
Product central artifactid dom4j-1.6.1 High
Product file name dom4j High
Product central artifactid dom4j High
Product pom groupid dom4j Low
Version file version 1.6.1 Highest
Version Manifest Implementation-Version 1.6.1 High
Published Vulnerabilities
CVE-2018-1000632 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Vulnerable Software & Versions: (show all )
hibernate-jpa-2.0-api-1.0.1.Final.jar
Description:
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
License:
license.txt
File Path: /home/ciagent/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.0-api/1.0.1.Final/hibernate-jpa-2.0-api-1.0.1.Final.jar
MD5: d7e7d8f60fc44a127ba702d43e71abec
SHA1: 3306a165afa81938fc3d8a0948e891de9f6b192b
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor hibernate.org High
Vendor pom groupid org.hibernate.javax.persistence Highest
Vendor pom organization name Hibernate.org High
Vendor pom url http://hibernate.org Highest
Vendor pom artifactid hibernate-jpa-2.0-api Low
Vendor pom name JPA 2.0 API High
Vendor pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Vendor pom groupid hibernate.javax.persistence Highest
Vendor pom organization url http://hibernate.org Medium
Vendor file name hibernate-jpa-2.0-api-1.0.1.Final High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor central groupid org.hibernate.javax.persistence Highest
Product pom groupid hibernate.javax.persistence Low
Product pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product Manifest Implementation-Title JPA API High
Product central artifactid hibernate-jpa-2.0-api Highest
Product pom organization url http://hibernate.org Low
Product pom artifactid hibernate-jpa-2.0-api Highest
Product Manifest specification-title Java Persistence API, Version 2.0 Medium
Product file name hibernate-jpa-2.0-api-1.0.1.Final High
Product pom organization name Hibernate.org Low
Product pom url http://hibernate.org Medium
Product pom name JPA 2.0 API High
Version pom version 1.0.1.Final Highest
Version central version 1.0.1.Final Highest
Version Manifest Implementation-Version 1.0.1.Final High
jboss-logging-annotations-1.2.0.Beta1.jar
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging-annotations/1.2.0.Beta1/jboss-logging-annotations-1.2.0.Beta1.jar
MD5: 938e552e319015a8863dd91284aada54
SHA1: 2f437f37bb265d9f8f1392823dbca12d2bec06d6
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.jboss.logging Highest
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Vendor central groupid org.jboss.logging Highest
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor file name jboss-logging-annotations High
Vendor pom groupid jboss.logging Highest
Vendor pom parent-groupid org.jboss.logging Medium
Vendor Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Vendor pom name JBoss Logging I18n Annotations High
Vendor Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest os-name Linux Medium
Vendor pom artifactid jboss-logging-annotations Low
Product pom groupid jboss.logging Low
Product pom parent-artifactid jboss-logging-tools-parent Medium
Product file name jboss-logging-annotations High
Product Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Product pom name JBoss Logging I18n Annotations High
Product Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Product pom artifactid jboss-logging-annotations Highest
Product Manifest specification-title JBoss Logging I18n Annotations Medium
Product Manifest Implementation-Title JBoss Logging I18n Annotations High
Product central artifactid jboss-logging-annotations Highest
Product Manifest os-name Linux Medium
Product pom parent-groupid org.jboss.logging Low
Version pom version 1.2.0.Beta1 Highest
Version central version 1.2.0.Beta1 Highest
Version Manifest Implementation-Version 1.2.0.Beta1 High
hibernate-commons-annotations-4.0.5.Final.jar
Description: Common reflection code used in support of annotation processing
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/common/hibernate-commons-annotations/4.0.5.Final/hibernate-commons-annotations-4.0.5.Final.jar
MD5: 5dadbafd7c7bc1168c10a2ba87e927a2
SHA1: 2a581b9edb8168e45060d8bad8b7f46712d2c52c
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Hibernate Commons Annotations High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom organization name Hibernate.org High
Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Vendor pom url http://hibernate.org Highest
Vendor pom artifactid hibernate-commons-annotations Low
Vendor pom description Common reflection code used in support of annotation processing Medium
Vendor central groupid org.hibernate.common Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor pom groupid org.hibernate.common Highest
Vendor file name hibernate-commons-annotations High
Vendor pom groupid hibernate.common Highest
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest implementation-url http://hibernate.org Low
Product pom groupid hibernate.common Low
Product central artifactid hibernate-commons-annotations Highest
Product pom name Hibernate Commons Annotations High
Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Product Manifest Bundle-Name hibernate-commons-annotations Medium
Product pom description Common reflection code used in support of annotation processing Medium
Product pom url http://hibernate.org Medium
Product file name hibernate-commons-annotations High
Product pom organization url http://hibernate.org Low
Product pom artifactid hibernate-commons-annotations Highest
Product pom organization name Hibernate.org Low
Product Manifest implementation-url http://hibernate.org Low
Version Manifest Implementation-Version 4.0.5.Final High
Version central version 4.0.5.Final Highest
Version file version 4.0.5 Highest
Version pom version 4.0.5.Final Highest
hibernate-core-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-core/4.2.21.Final/hibernate-core-4.2.21.Final.jar
MD5: 492567c1f36fb3a5968ca2d3c452edaf
SHA1: bb587d00287c13d9e4324bc76c13abbd493efa81
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom organization name Hibernate.org High
Vendor Manifest bundle-symbolicname org.hibernate.core Medium
Vendor pom url http://hibernate.org Highest
Vendor pom artifactid hibernate-core Low
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor central groupid org.hibernate Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor manifest Bundle-Description Hibernate ORM Core Medium
Vendor pom organization url http://hibernate.org Medium
Vendor file name hibernate-core High
Vendor pom groupid org.hibernate Highest
Vendor pom groupid hibernate Highest
Vendor pom name A Hibernate O/RM Module High
Vendor Manifest implementation-url http://hibernate.org Low
Product pom artifactid hibernate-core Highest
Product central artifactid hibernate-core Highest
Product Manifest bundle-symbolicname org.hibernate.core Medium
Product pom description A module of the Hibernate O/RM project Medium
Product pom url http://hibernate.org Medium
Product manifest Bundle-Description Hibernate ORM Core Medium
Product Manifest Bundle-Name hibernate-core Medium
Product file name hibernate-core High
Product pom groupid hibernate Low
Product pom organization url http://hibernate.org Low
Product pom organization name Hibernate.org Low
Product pom name A Hibernate O/RM Module High
Product Manifest implementation-url http://hibernate.org Low
Version file version 4.2.21 Highest
Version central version 4.2.21.Final Highest
Version pom version 4.2.21.Final Highest
Version Manifest Implementation-Version 4.2.21.Final High
jakarta-regexp-1.4.jar
File Path: /home/ciagent/.m2/repository/jakarta-regexp/jakarta-regexp/1.4/jakarta-regexp-1.4.jar
MD5: 5d8b8c601c21b37aa6142d38f45c0297
SHA1: 0ea514a179ac1dd7e81c7e6594468b9b9910d298
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jakarta-regexp Low
Vendor central groupid jakarta-regexp Highest
Vendor pom groupid jakarta-regexp Highest
Vendor jar package name apache Low
Vendor file name jakarta-regexp High
Vendor jar package name regexp Low
Product pom groupid jakarta-regexp Low
Product file name jakarta-regexp High
Product central artifactid jakarta-regexp Highest
Product pom artifactid jakarta-regexp Highest
Product jar package name regexp Low
Version central version 1.4 Highest
Version file version 1.4 Highest
Version pom version 1.4 Highest
xpp3-1.1.6.jar
Description: XML Pull parser library developed by Extreme Computing Lab, Indiana University
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ogce/xpp3/1.1.6/xpp3-1.1.6.jar
MD5: 626a429318310e92e3466151e050bdc5
SHA1: dc87e00ddb69341b46a3eb1c331c6fcebf6c8546
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name builder Low
Vendor pom url http://www.extreme.indiana.edu/xpp/ Highest
Vendor pom artifactid xpp3 Low
Vendor jar package name xmlpull Low
Vendor jar package name v1 Low
Vendor pom groupid ogce Highest
Vendor file name xpp3 High
Vendor central groupid org.ogce Highest
Vendor pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Vendor pom name XPP3 High
Vendor pom groupid org.ogce Highest
Product pom groupid ogce Low
Product jar package name builder Low
Product jar package name v1 Low
Product file name xpp3 High
Product pom url http://www.extreme.indiana.edu/xpp/ Medium
Product central artifactid xpp3 Highest
Product jar package name xpath Low
Product pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Product pom artifactid xpp3 Highest
Product pom name XPP3 High
Version file version 1.1.6 Highest
Version central version 1.1.6 Highest
Version pom version 1.1.6 Highest
exo.core.component.organization.api-5.3.x-SNAPSHOT.jar
Description: API of Organization Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.organization.api/5.3.x-SNAPSHOT/exo.core.component.organization.api-5.3.x-SNAPSHOT.jar
MD5: dac80c845342c757a54f5b1c780c52d6
SHA1: a07f68213aab5a6dd25dfcc8780e4162c59a7673
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.organization.api Low
Vendor pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom name eXo PLF Core :: Component :: Organization Service API High
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor file name exo.core.component.organization.api High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.core Medium
Product pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Product pom name eXo PLF Core :: Component :: Organization Service API High
Product pom parent-artifactid core-parent Medium
Product pom artifactid exo.core.component.organization.api Highest
Product file name exo.core.component.organization.api High
Product Manifest Implementation-Title eXo PLF Core :: Component :: Organization Service API High
Product pom groupid exoplatform.core Low
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
cpe: cpe:/a:api-platform:core:5.3
Confidence :Low
suppress
maven: org.exoplatform.core:exo.core.component.organization.api:5.3.x-SNAPSHOT
Confidence :High
quartz-2.2.2.jar
Description: Enterprise Job Scheduler
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
Apache Software License, Version 2.0
File Path: /home/ciagent/.m2/repository/org/quartz-scheduler/quartz/2.2.2/quartz-2.2.2.jar
MD5: 6acfd6ada2f4ad0abf4de916654dcaea
SHA1: 6fd24da6803ab7c3a08bc519a62219a9bebeb0df
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name quartz High
Vendor Manifest buildinfo-host tc-c65-jenkins-slave-001.eur.ad.sag Low
Vendor pom description Enterprise Job Scheduler Medium
Vendor Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.2 Low
Vendor Manifest buildinfo-timestamp 20151012-045213 Low
Vendor pom artifactid quartz Low
Vendor pom name quartz High
Vendor Manifest bundle-docurl http://www.terracotta.org Low
Vendor Manifest buildinfo-user jenkins-slave Low
Vendor pom groupid quartz-scheduler Highest
Vendor manifest Bundle-Description Enterprise Job Scheduler Medium
Vendor central groupid org.quartz-scheduler Highest
Vendor manifest terracotta-description Enterprise Job Scheduler Medium
Vendor pom parent-artifactid quartz-parent Low
Vendor Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium
Vendor Manifest buildinfo-revision 2464 Low
Vendor pom parent-groupid org.quartz-scheduler Medium
Vendor pom groupid org.quartz-scheduler Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest terracotta-name quartz Medium
Product file name quartz High
Product Manifest buildinfo-host tc-c65-jenkins-slave-001.eur.ad.sag Low
Product pom parent-artifactid quartz-parent Medium
Product pom description Enterprise Job Scheduler Medium
Product Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.2 Low
Product Manifest buildinfo-timestamp 20151012-045213 Low
Product pom groupid quartz-scheduler Low
Product Manifest Bundle-Name quartz Medium
Product pom name quartz High
Product Manifest bundle-docurl http://www.terracotta.org Low
Product Manifest buildinfo-user jenkins-slave Low
Product pom parent-groupid org.quartz-scheduler Low
Product central artifactid quartz Highest
Product manifest Bundle-Description Enterprise Job Scheduler Medium
Product pom artifactid quartz Highest
Product manifest terracotta-description Enterprise Job Scheduler Medium
Product Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium
Product Manifest buildinfo-revision 2464 Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest terracotta-name quartz Medium
Version pom version 2.2.2 Highest
Version central version 2.2.2 Highest
Version file version 2.2.2 Highest
commons-pool-1.6.jar
Description: Commons Object Pooling Library
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Commons Pool High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Vendor file name commons-pool High
Vendor pom groupid commons-pool Highest
Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium
Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low
Vendor manifest Bundle-Description Commons Object Pooling Library Medium
Vendor pom url http://commons.apache.org/pool/ Highest
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-pool Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom description Commons Object Pooling Library Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-pool Highest
Product pom name Commons Pool High
Product Manifest Bundle-Name Commons Pool Medium
Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Product pom parent-artifactid commons-parent Medium
Product file name commons-pool High
Product pom parent-groupid org.apache.commons Low
Product Manifest bundle-symbolicname org.apache.commons.pool Medium
Product Manifest bundle-docurl http://commons.apache.org/pool/ Low
Product manifest Bundle-Description Commons Object Pooling Library Medium
Product central artifactid commons-pool Highest
Product Manifest specification-title Commons Pool Medium
Product pom groupid commons-pool Low
Product pom url http://commons.apache.org/pool/ Medium
Product pom description Commons Object Pooling Library Medium
Product pom artifactid commons-pool Highest
Product Manifest Implementation-Title Commons Pool High
Version pom version 1.6 Highest
Version file version 1.6 Highest
Version Manifest Implementation-Version 1.6 High
Version central version 1.6 Highest
exo.kernel.component.common-5.3.x-SNAPSHOT.jar
Description: Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.common/5.3.x-SNAPSHOT/exo.kernel.component.common-5.3.x-SNAPSHOT.jar
MD5: c57430ba3cc88079d9fe4604fed4798c
SHA1: d3f3536bcb0b5ed4306eaf6896f22d022f844899
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor file name exo.kernel.component.common High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom artifactid exo.kernel.component.common Low
Vendor pom name eXo PLF:: Kernel :: Component :: Common Service High
Product pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product file name exo.kernel.component.common High
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Common Service High
Product Manifest specification-title exo-kernel Medium
Product pom groupid exoplatform.kernel Low
Product pom artifactid exo.kernel.component.common Highest
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Component :: Common Service High
Version pom version 5.3.x-20190523.135326-2 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.common:5.3.x-SNAPSHOT
Confidence :High
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor file name commons-lang High
Vendor pom name Commons Lang High
Vendor pom groupid commons-lang Highest
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor central groupid org.netbeans.external High
Vendor pom artifactid commons-lang Low
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-lang High
Product Manifest Bundle-Name Commons Lang Medium
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product pom parent-artifactid commons-parent Medium
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product file name commons-lang High
Product central artifactid org-apache-commons-lang High
Product pom name Commons Lang High
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-lang High
Product Manifest specification-title Commons Lang Medium
Product Manifest Implementation-Title Commons Lang High
Product pom groupid commons-lang Low
Product pom artifactid commons-lang Highest
Product pom url http://commons.apache.org/lang/ Medium
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Version central version RELEASE90 High
Version central version RELEASE110 High
Version pom version 2.6 Highest
Version central version RELEASE100 High
Version Manifest Implementation-Version 2.6 High
Version central version 2.6 High
Version file version 2.6 Highest
exo.core.component.security.core-5.3.x-SNAPSHOT.jar
Description: Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.security.core/5.3.x-SNAPSHOT/exo.core.component.security.core-5.3.x-SNAPSHOT.jar
MD5: 488f425f279a0c228294112bce69f54a
SHA1: 851b19507264b0f4a9f19d3752df3b127276ce2a
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom name eXo PLF Core :: Component :: Security Service High
Vendor file name exo.core.component.security.core High
Vendor pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom artifactid exo.core.component.security.core Low
Product pom artifactid exo.core.component.security.core Highest
Product Manifest Implementation-Title eXo PLF Core :: Component :: Security Service High
Product pom parent-artifactid core-parent Medium
Product pom name eXo PLF Core :: Component :: Security Service High
Product file name exo.core.component.security.core High
Product pom groupid exoplatform.core Low
Product pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.security.core:5.3.x-SNAPSHOT
Confidence :High
commons-chain-1.2.jar
Description:
An implementation of the GoF Chain of Responsibility pattern
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-chain/commons-chain/1.2/commons-chain-1.2.jar
MD5: e18e2c87826644e4c8c08635572c154f
SHA1: 744a13e8766e338bd347b6fbc28c6db12979d0c6
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom artifactid commons-chain Low
Vendor Manifest bundle-docurl http://commons.apache.org/chain/ Low
Vendor central groupid commons-chain Highest
Vendor Manifest bundle-symbolicname org.apache.commons.chain Medium
Vendor pom groupid commons-chain Highest
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Vendor pom url http://commons.apache.org/chain/ Highest
Vendor file name commons-chain High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom name Commons Chain High
Product pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest specification-title Commons Chain Medium
Product pom groupid commons-chain Low
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-chain Highest
Product pom artifactid commons-chain Highest
Product Manifest bundle-docurl http://commons.apache.org/chain/ Low
Product Manifest Implementation-Title Commons Chain High
Product Manifest bundle-symbolicname org.apache.commons.chain Medium
Product Manifest Bundle-Name Commons Chain Medium
Product manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Product file name commons-chain High
Product pom name Commons Chain High
Product pom url http://commons.apache.org/chain/ Medium
Version pom version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
Version file version 1.2 Highest
commons-digester-2.1.jar
Description:
The Digester package lets you configure an XML to Java object mapping module
which triggers certain actions called rules whenever a particular
pattern of nested XML elements is recognized.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom url http://commons.apache.org/digester/ Highest
Vendor pom artifactid commons-digester Low
Vendor pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor central groupid commons-digester Highest
Vendor Manifest bundle-symbolicname org.apache.commons.digester Medium
Vendor pom name Commons Digester High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor pom groupid commons-digester Highest
Vendor file name commons-digester High
Vendor Manifest bundle-docurl http://commons.apache.org/digester/ Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom parent-artifactid commons-parent Medium
Product Manifest specification-title Commons Digester Medium
Product Manifest Implementation-Title Commons Digester High
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-digester Highest
Product pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product pom groupid commons-digester Low
Product pom url http://commons.apache.org/digester/ Medium
Product Manifest bundle-symbolicname org.apache.commons.digester Medium
Product pom name Commons Digester High
Product pom artifactid commons-digester Highest
Product Manifest Bundle-Name Commons Digester Medium
Product manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product file name commons-digester High
Product Manifest bundle-docurl http://commons.apache.org/digester/ Low
Version pom version 2.1 Highest
Version Manifest Implementation-Version 2.1 High
Version central version 2.1 Highest
Version file version 2.1 Highest
exo.kernel.component.command-5.3.x-SNAPSHOT.jar
Description: Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.command/5.3.x-SNAPSHOT/exo.kernel.component.command-5.3.x-SNAPSHOT.jar
MD5: c8e34b4521db08641687547b1fbc1ce5
SHA1: 1527c8dccb38e62fb298b68bda8263e9005bc6c1
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom artifactid exo.kernel.component.command Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor file name exo.kernel.component.command High
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom name eXo PLF:: Kernel :: Component :: Command Service High
Product Manifest specification-title exo-kernel Medium
Product pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product file name exo.kernel.component.command High
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Command Service High
Product pom parent-groupid org.exoplatform.kernel Low
Product pom artifactid exo.kernel.component.command Highest
Product pom name eXo PLF:: Kernel :: Component :: Command Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.command:5.3.x-SNAPSHOT
Confidence :High
commons-io-2.4.jar
Description:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-io/commons-io/2.4/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.io Medium
Vendor manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Vendor pom groupid commons-io Highest
Vendor file name commons-io High
Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low
Vendor central groupid commons-io Highest
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Commons IO High
Vendor pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid commons-io Low
Vendor pom url http://commons.apache.org/io/ Highest
Product pom parent-artifactid commons-parent Medium
Product pom groupid commons-io Low
Product pom artifactid commons-io Highest
Product Manifest bundle-symbolicname org.apache.commons.io Medium
Product pom parent-groupid org.apache.commons Low
Product Manifest specification-title Commons IO Medium
Product manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Product Manifest Implementation-Title Commons IO High
Product file name commons-io High
Product Manifest bundle-docurl http://commons.apache.org/io/ Low
Product Manifest Bundle-Name Commons IO Medium
Product pom name Commons IO High
Product pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product pom url http://commons.apache.org/io/ Medium
Product central artifactid commons-io Highest
Version pom version 2.4 Highest
Version central version 2.4 Highest
Version file version 2.4 Highest
Version Manifest Implementation-Version 2.4 High
fontbox-1.8.14.jar
Description:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/fontbox/1.8.14/fontbox-1.8.14.jar
MD5: 901640f7e2bd12508ae4a7cccba3df79
SHA1: 9c7caec614a6a132bedc83f1d6d247bb96ca0df3
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.pdfbox Highest
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor pom url http://pdfbox.apache.org/ Highest
Vendor central groupid org.apache.pdfbox Highest
Vendor manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom parent-artifactid pdfbox-parent Low
Vendor file name fontbox High
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom name Apache FontBox High
Vendor pom artifactid fontbox Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Product central artifactid fontbox Highest
Product Manifest specification-title Apache FontBox Medium
Product manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product pom artifactid fontbox Highest
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom groupid apache.pdfbox Low
Product Manifest Implementation-Title Apache FontBox High
Product Manifest Bundle-Name Apache FontBox Medium
Product file name fontbox High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom name Apache FontBox High
Product pom parent-groupid org.apache.pdfbox Low
Product pom url http://pdfbox.apache.org/ Medium
Product pom parent-artifactid pdfbox-parent Medium
Product pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
jempbox-1.8.14.jar
Description:
The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM)
specification. JempBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/jempbox/1.8.14/jempbox-1.8.14.jar
MD5: 393135759731daf4e301903b3de2fbbb
SHA1: 7f94c7cd4efc21e78729436cc4cf0c09eeea0f38
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.pdfbox Highest
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor file name jempbox High
Vendor manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom name Apache JempBox High
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom artifactid jempbox Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product Manifest specification-title Apache JempBox Medium
Product pom artifactid jempbox Highest
Product Manifest Bundle-Name Apache JempBox Medium
Product file name jempbox High
Product manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom groupid apache.pdfbox Low
Product pom name Apache JempBox High
Product Manifest Implementation-Title Apache JempBox High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom parent-groupid org.apache.pdfbox Low
Product central artifactid jempbox Highest
Product pom parent-artifactid pdfbox-parent Medium
Product Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
pdfbox-1.8.14.jar
Description:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/pdfbox/1.8.14/pdfbox-1.8.14.jar
MD5: c90740e185fc2f8013d1119f509ea4f3
SHA1: 7550298240c8540b721733ede6dc88fcf4fa2b0f
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.pdfbox Highest
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom artifactid pdfbox Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Vendor manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor file name pdfbox High
Vendor pom name Apache PDFBox High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product Manifest Bundle-Name Apache PDFBox Medium
Product Manifest bundle-symbolicname org.apache.pdfbox Medium
Product Manifest Implementation-Title Apache PDFBox High
Product pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Product central artifactid pdfbox Highest
Product Manifest specification-title Apache PDFBox Medium
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom groupid apache.pdfbox Low
Product pom artifactid pdfbox Highest
Product manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom parent-groupid org.apache.pdfbox Low
Product file name pdfbox High
Product pom parent-artifactid pdfbox-parent Medium
Product pom name Apache PDFBox High
Version file version 1.8.14 Highest
Version central version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version pom version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
htmllexer-2.1.jar
Description: HTML Lexer is the low level lexical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmllexer/2.1/htmllexer-2.1.jar
MD5: 1cb7184766a0c52f4d98d671bb08be19
SHA1: 2ebf2c073e649b7e674cddd0558ff102a486402f
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description HTML Lexer is the low level lexical analyzer. Medium
Vendor pom parent-artifactid HTMLParserProject Low
Vendor file name htmllexer High
Vendor pom url http://htmlparser.org Highest
Vendor pom parent-groupid org.htmlparser Medium
Vendor pom artifactid htmllexer Low
Vendor pom groupid org.htmlparser Highest
Vendor jar package name htmlparser Low
Vendor pom groupid htmlparser Highest
Vendor pom name HTML Lexer Jar High
Vendor central groupid org.htmlparser Highest
Product pom parent-groupid org.htmlparser Low
Product pom description HTML Lexer is the low level lexical analyzer. Medium
Product file name htmllexer High
Product central artifactid htmllexer Highest
Product pom groupid htmlparser Low
Product pom parent-artifactid HTMLParserProject Medium
Product pom url http://htmlparser.org Medium
Product pom artifactid htmllexer Highest
Product pom name HTML Lexer Jar High
Version pom version 2.1 Highest
Version central version 2.1 Highest
Version file version 2.1 Highest
htmlparser-2.1.jar
Description: HTML Parser is the high level syntactical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmlparser/2.1/htmlparser-2.1.jar
MD5: aa05b921026c228f92ef8b4a13c26f8d
SHA1: c752e5984b7767533cbd3fdffa48cecb52fa226c
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid HTMLParserProject Low
Vendor pom artifactid htmlparser Low
Vendor pom url http://htmlparser.org Highest
Vendor pom parent-groupid org.htmlparser Medium
Vendor pom groupid org.htmlparser Highest
Vendor jar package name htmlparser Low
Vendor file name htmlparser High
Vendor pom groupid htmlparser Highest
Vendor pom name HTML Parser Jar High
Vendor pom description HTML Parser is the high level syntactical analyzer. Medium
Vendor central groupid org.htmlparser Highest
Product pom parent-groupid org.htmlparser Low
Product pom artifactid htmlparser Highest
Product pom groupid htmlparser Low
Product file name htmlparser High
Product pom parent-artifactid HTMLParserProject Medium
Product pom name HTML Parser Jar High
Product pom url http://htmlparser.org Medium
Product central artifactid htmlparser Highest
Product pom description HTML Parser is the high level syntactical analyzer. Medium
Version pom version 2.1 Highest
Version central version 2.1 Highest
Version file version 2.1 Highest
commons-codec-1.10.jar
Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Vendor manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Vendor central groupid commons-codec Highest
Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium
Vendor pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor pom groupid commons-codec Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor file name commons-codec High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Apache Commons Codec High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid commons-codec Low
Product central artifactid commons-codec Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Product manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-codec Highest
Product Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Product pom groupid commons-codec Low
Product pom parent-groupid org.apache.commons Low
Product pom url http://commons.apache.org/proper/commons-codec/ Medium
Product Manifest bundle-symbolicname org.apache.commons.codec Medium
Product pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product file name commons-codec High
Product Manifest Implementation-Title Apache Commons Codec High
Product pom name Apache Commons Codec High
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest specification-title Apache Commons Codec Medium
Version file version 1.10 Highest
Version Manifest Implementation-Version 1.10 High
Version central version 1.10 Highest
Version pom version 1.10 Highest
poi-3.13.jar
Description: Apache POI - Java API To Access Microsoft Format Files
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi/3.13/poi-3.13.jar
MD5: 1b43f32e2211546040597a9e2d07b869
SHA1: 0f59f504ba8c521e61e25f417ec652fd485010f3
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name poi High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom url http://poi.apache.org/ Highest
Vendor pom groupid org.apache.poi Highest
Vendor pom description Apache POI - Java API To Access Microsoft Format Files Medium
Vendor pom groupid apache.poi Highest
Vendor central groupid org.apache.poi Highest
Vendor pom artifactid poi Low
Vendor pom name Apache POI High
Vendor pom organization name Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor pom organization url http://www.apache.org/ Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product file name poi High
Product central artifactid poi Highest
Product pom artifactid poi Highest
Product pom name Apache POI High
Product pom groupid apache.poi Low
Product pom description Apache POI - Java API To Access Microsoft Format Files Medium
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom url http://poi.apache.org/ Medium
Version Manifest Implementation-Version 3.13 High
Version central version 3.13 Highest
Version file version 3.13 Highest
Version pom version 3.13 Highest
Related Dependencies
poi-ooxml-schemas-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml-schemas/3.13/poi-ooxml-schemas-3.13.jar
SHA1: 56fb0b9f3ffc3d7f7fc9b59e17b5fa2c3ab921e7
MD5: ca12e13961e9df83ddd5471733d73d91
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml-schemas:3.13 ✓
poi-scratchpad-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-scratchpad/3.13/poi-scratchpad-3.13.jar
SHA1: 09d763275e6c7fa05d47e2581606748669e88c55
MD5: d8dbe05b289da779874e4783881e1b57
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-scratchpad:3.13 ✓
poi-ooxml-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml/3.13/poi-ooxml-3.13.jar
SHA1: c364a8f5422d613e3a56db3b4b889f2989d7ee73
MD5: 38bb36c35a16030d4bc0ac14421430d7
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml:3.13 ✓
Published Vulnerabilities
CVE-2016-5000 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Vulnerable Software & Versions:
CVE-2017-5644 suppress
Severity:
High
CVSS Score: 7.1
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Vulnerable Software & Versions:
tika-core-1.5.jar
Description: This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-core/1.5/tika-core-1.5.jar
MD5: e864bf637f51283dc525087b015d7b1a
SHA1: 194ca0fb3d73b07737524806fbc3bec89063c03a
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid apache.tika Highest
Vendor pom artifactid tika-core Low
Vendor central groupid org.apache.tika Highest
Vendor Manifest bundle-symbolicname org.apache.tika.core Medium
Vendor pom parent-groupid org.apache.tika Medium
Vendor Manifest bundle-docurl http://tika.apache.org/ Low
Vendor pom groupid org.apache.tika Highest
Vendor pom organization url http://www.apache.org Medium
Vendor manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor pom name Apache Tika core High
Vendor pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor pom organization name The Apache Software Foundation High
Vendor file name tika-core High
Vendor pom parent-artifactid tika-parent Low
Vendor pom url http://tika.apache.org/ Highest
Product Manifest Bundle-Name Apache Tika core Medium
Product Manifest bundle-symbolicname org.apache.tika.core Medium
Product Manifest bundle-docurl http://tika.apache.org/ Low
Product central artifactid tika-core Highest
Product manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product pom name Apache Tika core High
Product pom parent-artifactid tika-parent Medium
Product pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product pom artifactid tika-core Highest
Product pom groupid apache.tika Low
Product pom parent-groupid org.apache.tika Low
Product pom url http://tika.apache.org/ Medium
Product file name tika-core High
Product pom organization name The Apache Software Foundation Low
Product pom organization url http://www.apache.org Low
Version pom version 1.5 Highest
Version central version 1.5 Highest
Version file version 1.5 Highest
Related Dependencies
tika-parsers-1.5.jar
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-parsers/1.5/tika-parsers-1.5.jar
SHA1: 9b895231b7a0dae7349dfb42cb1b926c345b5281
MD5: f1056da5d1021ad1bbac7dab01b335d1
cpe: cpe:/a:apache:tika:1.5
maven: org.apache.tika:tika-parsers:1.5 ✓
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11762 suppress
Severity:
Medium
CVSS Score: 5.8
(AV:N/AC:M/Au:N/C:N/I:P/A:P)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-8017 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Vulnerable Software & Versions: (show all )
vorbis-java-core-0.1-tests.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1-tests.jar
MD5: d58f076c08a917277d03f3417aa867a6
SHA1: c849979e199d8a7c3da1a00799c623c00f94efac
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:test,provided
Evidence
Type Source Name Value Confidence
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom groupid org.gagravarr Highest
Vendor file name vorbis-java-core High
Vendor pom parent-groupid org.gagravarr Medium
Vendor central groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor pom artifactid vorbis-java-core Low
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor jar package name gagravarr Low
Vendor jar package name ogg Low
Vendor pom name Ogg and Vorbis for Java, Core High
Product pom url Gagravarr/VorbisJava High
Product central artifactid vorbis-java-core Highest
Product file name vorbis-java-core High
Product pom parent-groupid org.gagravarr Low
Product jar package name ogg Low
Product pom artifactid vorbis-java-core Highest
Product pom parent-artifactid vorbis-java-parent Medium
Product pom groupid gagravarr Low
Product pom name Ogg and Vorbis for Java, Core High
Version pom version 0.1 Highest
Version file version 0.1 Highest
Version central version 0.1 Highest
vorbis-java-tika-0.1.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-tika/0.1/vorbis-java-tika-0.1.jar
MD5: 1fccc6796a0924ba4f32eb1d44b8616b
SHA1: 6966c8663a7f689021accb13cceaa6101f53ea3d
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url Gagravarr/VorbisJava Highest
Vendor jar package name tika Low
Vendor pom groupid org.gagravarr Highest
Vendor pom artifactid vorbis-java-tika Low
Vendor pom parent-groupid org.gagravarr Medium
Vendor central groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Vendor jar package name gagravarr Low
Vendor file name vorbis-java-tika High
Product jar package name tika Low
Product pom artifactid vorbis-java-tika Highest
Product pom url Gagravarr/VorbisJava High
Product pom parent-groupid org.gagravarr Low
Product pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Product pom parent-artifactid vorbis-java-parent Medium
Product central artifactid vorbis-java-tika Highest
Product file name vorbis-java-tika High
Product pom groupid gagravarr Low
Version pom version 0.1 Highest
Version file version 0.1 Highest
Version central version 0.1 Highest
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
netcdf-4.2-min.jar
Description: The NetCDF-Java Library is a Java interface to NetCDF files,
as well as to many other types of scientific data formats.
License:
(MIT-style) netCDF C library license.: http://www.unidata.ucar.edu/software/netcdf/copyright.html
File Path: /home/ciagent/.m2/repository/edu/ucar/netcdf/4.2-min/netcdf-4.2-min.jar
MD5: eb00b40b0511f0fc1dfcfc9cb89e3c53
SHA1: 0f3c3f3db4c54483aa1fbc4497e300879ce24da1
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid edu.ucar Highest
Vendor file name netcdf High
Vendor pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/ Highest
Vendor Manifest built-on 2010-11-24 05:51:29 Low
Vendor pom name The NetCDF-Java Library High
Vendor pom artifactid netcdf Low
Vendor central groupid edu.ucar Highest
Vendor Manifest Implementation-Vendor UCAR/Unidata High
Product pom groupid edu.ucar Low
Product file name netcdf High
Product pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Product central artifactid netcdf Highest
Product Manifest built-on 2010-11-24 05:51:29 Low
Product pom name The NetCDF-Java Library High
Product Manifest Implementation-Title NetCDF-Java-Library High
Product pom url http://www.unidata.ucar.edu/software/netcdf-java/ Medium
Product pom artifactid netcdf Highest
Version file version 4.2 Highest
Version pom version 4.2-min Highest
Version central version 4.2-min Highest
apache-mime4j-core-0.7.2.jar
Description: Java stream based MIME message parser
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-core/0.7.2/apache-mime4j-core-0.7.2.jar
MD5: 88f799546eca803c53eee01a4ce5edcd
SHA1: a81264fe0265ebe8fd1d8128aad06dc320de6eef
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid apache-mime4j-core Low
Vendor pom groupid org.apache.james Highest
Vendor pom parent-groupid org.apache.james Medium
Vendor Manifest bundle-docurl http://www.apache.org/ Low
Vendor pom groupid apache.james Highest
Vendor central groupid org.apache.james Highest
Vendor file name apache-mime4j-core High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-artifactid apache-mime4j-project Low
Vendor pom name Apache JAMES Mime4j (Core) High
Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Vendor manifest Bundle-Description Java stream based MIME message parser Medium
Vendor Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product Manifest bundle-docurl http://www.apache.org/ Low
Product central artifactid apache-mime4j-core Highest
Product Manifest Bundle-Name Apache JAMES Mime4j (Core) Medium
Product pom parent-groupid org.apache.james Low
Product file name apache-mime4j-core High
Product pom name Apache JAMES Mime4j (Core) High
Product Manifest specification-title Apache Mime4j Medium
Product pom groupid apache.james Low
Product pom parent-artifactid apache-mime4j-project Medium
Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Product manifest Bundle-Description Java stream based MIME message parser Medium
Product pom artifactid apache-mime4j-core Highest
Product Manifest Implementation-Title Apache Mime4j High
Product Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Version pom version 0.7.2 Highest
Version Manifest Implementation-Version 0.7.2 High
Version central version 0.7.2 Highest
Version file version 0.7.2 Highest
Related Dependencies
apache-mime4j-dom-0.7.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-dom/0.7.2/apache-mime4j-dom-0.7.2.jar
SHA1: 1c289aa264548a0a1f1b43685a9cb2ab23f67287
MD5: dedc747b5c367fbd7f8a7235d1d7cbee
maven: org.apache.james:apache-mime4j-dom:0.7.2 ✓
xz-1.2.jar
Description: XZ data compression
License:
Public Domain
File Path: /home/ciagent/.m2/repository/org/tukaani/xz/1.2/xz-1.2.jar
MD5: 04bd31459826c30c2a3c304e3b225ad4
SHA1: bfc66dda280a18ab341b5023248925265c00394c
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url http://tukaani.org/xz/java.html Low
Vendor Manifest bundle-symbolicname org.tukaani.xz Medium
Vendor pom groupid tukaani Highest
Vendor pom name XZ for Java High
Vendor pom groupid org.tukaani Highest
Vendor pom description XZ data compression Medium
Vendor pom url http://tukaani.org/xz/java.html Highest
Vendor file name xz High
Vendor central groupid org.tukaani Highest
Vendor Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Vendor pom artifactid xz Low
Product pom artifactid xz Highest
Product pom name XZ for Java High
Product pom description XZ data compression Medium
Product central artifactid xz Highest
Product Manifest implementation-url http://tukaani.org/xz/java.html Low
Product Manifest bundle-symbolicname org.tukaani.xz Medium
Product pom url http://tukaani.org/xz/java.html Medium
Product file name xz High
Product Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Product pom groupid tukaani Low
Product Manifest Implementation-Title XZ data compression High
Product Manifest Bundle-Name XZ data compression Medium
Version pom version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
Version file version 1.2 Highest
maven: org.tukaani:xz:1.2 ✓
Confidence :Highest
cpe: cpe:/a:tukaani:xz:1.2
Confidence :Low
suppress
Published Vulnerabilities
CVE-2015-4035 suppress
Severity:
Medium
CVSS Score: 4.6
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
Vulnerable Software & Versions:
commons-compress-1.5.jar
Description:
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-compress/1.5/commons-compress-1.5.jar
MD5: 5e18cfcf472548c2e0b90a4ea1cedf42
SHA1: d2bd2c0bd328f1dabdf33e10b6d223ebcbe93343
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://commons.apache.org/compress/ Low
Vendor file name commons-compress High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.commons Highest
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest extension-name org.apache.commons.compress Medium
Vendor pom url http://commons.apache.org/compress/ Highest
Vendor pom name Commons Compress High
Vendor Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Vendor pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-compress Low
Vendor Manifest bundle-symbolicname org.apache.commons.compress Medium
Vendor central groupid org.apache.commons Highest
Vendor pom groupid org.apache.commons Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product Manifest bundle-docurl http://commons.apache.org/compress/ Low
Product file name commons-compress High
Product Manifest Implementation-Title Commons Compress High
Product pom parent-artifactid commons-parent Medium
Product Manifest extension-name org.apache.commons.compress Medium
Product pom name Commons Compress High
Product Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Product pom parent-groupid org.apache.commons Low
Product pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product pom url http://commons.apache.org/compress/ Medium
Product Manifest specification-title Commons Compress Medium
Product pom groupid apache.commons Low
Product manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product central artifactid commons-compress Highest
Product Manifest bundle-symbolicname org.apache.commons.compress Medium
Product Manifest Bundle-Name Commons Compress Medium
Product pom artifactid commons-compress Highest
Version pom version 1.5 Highest
Version central version 1.5 Highest
Version file version 1.5 Highest
Version Manifest Implementation-Version 1.5 High
bcmail-jdk15-1.45.jar
Description: The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. If the S/MIME API is used, the JavaMail API and the Java activation framework will also be needed.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcmail-jdk15/1.45/bcmail-jdk15-1.45.jar
MD5: 13321fc7eff7bcada7b4fedfb592025c
SHA1: 3aed7e642dd8d39dc14ed1dec3ff79e084637148
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.bouncycastle Highest
Vendor file name bcmail-jdk15 High
Vendor central groupid org.bouncycastle Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor pom artifactid bcmail-jdk15 Low
Vendor pom name Bouncy Castle CMS and S/MIME API High
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor pom groupid bouncycastle Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor Manifest extension-name org.bouncycastle.bcmail Medium
Product pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Product pom url http://www.bouncycastle.org/java.html Medium
Product file name bcmail-jdk15 High
Product central artifactid bcmail-jdk15 Highest
Product pom name Bouncy Castle CMS and S/MIME API High
Product pom groupid bouncycastle Low
Product Manifest extension-name org.bouncycastle.bcmail Medium
Product pom artifactid bcmail-jdk15 Highest
Version pom version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version file version 1.45 Highest
Version central version 1.45 Highest
bcprov-jdk15-1.45.jar
Description: The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcprov-jdk15/1.45/bcprov-jdk15-1.45.jar
MD5: 2062f8e3d15748443ea60a94b266371c
SHA1: 7741883cb07b4634e8b5fd3337113b6ea770a9bb
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.bouncycastle Highest
Vendor central groupid org.bouncycastle Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor pom artifactid bcprov-jdk15 Low
Vendor Manifest extension-name org.bouncycastle.bcprovider Medium
Vendor pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor pom groupid bouncycastle Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor file name bcprov-jdk15 High
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor pom name Bouncy Castle Provider High
Product file name bcprov-jdk15 High
Product pom url http://www.bouncycastle.org/java.html Medium
Product central artifactid bcprov-jdk15 Highest
Product Manifest extension-name org.bouncycastle.bcprovider Medium
Product pom artifactid bcprov-jdk15 Highest
Product pom name Bouncy Castle Provider High
Product pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Product pom groupid bouncycastle Low
Version pom version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version file version 1.45 Highest
Version central version 1.45 Highest
cpe: cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45
Confidence :Low
suppress
maven: org.bouncycastle:bcprov-jdk15:1.45 ✓
Confidence :Highest
cpe: cpe:/a:bouncycastle:bouncy_castle_crypto_package:1.45
Confidence :Low
suppress
Published Vulnerabilities
CVE-2015-7940 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
Vulnerable Software & Versions: (show all )
tagsoup-1.2.1.jar
Description: TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML.
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ccil/cowan/tagsoup/tagsoup/1.2.1/tagsoup-1.2.1.jar
MD5: ae73a52cdcbec10cd61d9ef22fab5936
SHA1: 5584627487e984c03456266d3f8802eb85a9ce97
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.ccil.cowan.tagsoup Highest
Vendor file name tagsoup High
Vendor pom groupid ccil.cowan.tagsoup Highest
Vendor pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low
Vendor pom url http://home.ccil.org/~cowan/XML/tagsoup/ Highest
Vendor pom artifactid tagsoup Low
Vendor central groupid org.ccil.cowan.tagsoup Highest
Vendor pom name TagSoup High
Product file name tagsoup High
Product pom groupid ccil.cowan.tagsoup Low
Product central artifactid tagsoup Highest
Product pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low
Product pom artifactid tagsoup Highest
Product pom name TagSoup High
Product pom url http://home.ccil.org/~cowan/XML/tagsoup/ Medium
Version central version 1.2.1 Highest
Version pom version 1.2.1 Highest
Version file version 1.2.1 Highest
asm-debug-all-4.1.jar
File Path: /home/ciagent/.m2/repository/org/ow2/asm/asm-debug-all/4.1/asm-debug-all-4.1.jar
MD5: 6c3a8842f484dd3d620002b361e3610e
SHA1: dd6ba5c392d4102458494e29f54f70ac534ec2a2
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.ow2.asm Medium
Vendor pom name ASM Debug All High
Vendor central groupid org.ow2.asm Highest
Vendor Manifest Implementation-Vendor France Telecom R&D High
Vendor file name asm-debug-all High
Vendor Manifest bundle-docurl http://asm.objectweb.org Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium
Vendor pom groupid ow2.asm Highest
Vendor pom groupid org.ow2.asm Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom parent-artifactid asm-parent Low
Vendor pom artifactid asm-debug-all Low
Product pom name ASM Debug All High
Product pom parent-groupid org.ow2.asm Low
Product pom parent-artifactid asm-parent Medium
Product pom groupid ow2.asm Low
Product file name asm-debug-all High
Product Manifest bundle-docurl http://asm.objectweb.org Low
Product Manifest Bundle-Name ASM all classes with debug info Medium
Product Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom artifactid asm-debug-all Highest
Product Manifest Implementation-Title ASM all classes with debug info High
Product central artifactid asm-debug-all Highest
Version central version 4.1 Highest
Version file version 4.1 Highest
Version pom version 4.1 Highest
Version Manifest Implementation-Version 4.1 High
aspectjrt-1.8.8.jar
Description: The runtime needed to execute a program using AspectJ
License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/ciagent/.m2/repository/org/aspectj/aspectjrt/1.8.8/aspectjrt-1.8.8.jar
MD5: 2e448cd7ae0bdc357cb2b6e892ba9c9d
SHA1: 7c5b26f24375685e34a50c2d765ebc40a96a5280
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid aspectj Highest
Vendor pom name AspectJ runtime High
Vendor manifest: org/aspectj/lang/ Implementation-Vendor aspectj.org Medium
Vendor pom description The runtime needed to execute a program using AspectJ Medium
Vendor pom groupid org.aspectj Highest
Vendor pom artifactid aspectjrt Low
Vendor file name aspectjrt High
Vendor central groupid org.aspectj Highest
Vendor pom url http://www.aspectj.org Highest
Product pom name AspectJ runtime High
Product pom description The runtime needed to execute a program using AspectJ Medium
Product pom url http://www.aspectj.org Medium
Product manifest: org/aspectj/lang/ Implementation-Title org.aspectj.tools Medium
Product pom artifactid aspectjrt Highest
Product manifest: org/aspectj/lang/ Specification-Title AspectJ Runtime Classes Medium
Product central artifactid aspectjrt Highest
Product file name aspectjrt High
Product pom groupid aspectj Low
Version file version 1.8.8 Highest
Version central version 1.8.8 Highest
Version pom version 1.8.8 Highest
isoparser-1.0-RC-1.jar
Description: A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/googlecode/mp4parser/isoparser/1.0-RC-1/isoparser-1.0-RC-1.jar
MD5: b0444fde2290319c9028564c3c3ff1ab
SHA1: 4a5768b1070b9488a433362d736720fd7a7b264f
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.googlecode.mp4parser Highest
Vendor jar package name coremedia Low
Vendor pom groupid googlecode.mp4parser Highest
Vendor file name isoparser High
Vendor pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium
Vendor pom artifactid isoparser Low
Vendor central groupid com.googlecode.mp4parser Highest
Vendor pom name ISO Parser High
Vendor jar package name boxes Low
Vendor pom url http://code.google.com/p/mp4parser/ Highest
Vendor jar package name iso Low
Product pom url http://code.google.com/p/mp4parser/ Medium
Product central artifactid isoparser Highest
Product file name isoparser High
Product pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium
Product pom artifactid isoparser Highest
Product pom name ISO Parser High
Product jar package name boxes Low
Product pom groupid googlecode.mp4parser Low
Product jar package name iso Low
Version file version 1.0 Highest
Version pom version 1.0-RC-1 Highest
Version file name isoparser Medium
Version central version 1.0-RC-1 Highest
Published Vulnerabilities
CVE-2013-0259 suppress
Severity:
Low
CVSS Score: 2.1
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.
Vulnerable Software & Versions: (show all )
xmpcore-5.1.2.jar
Description:
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
License:
The BSD License: http://www.adobe.com/devnet/xmp/library/eula-xmp-library-java.html
File Path: /home/ciagent/.m2/repository/com/adobe/xmp/xmpcore/5.1.2/xmpcore-5.1.2.jar
MD5: 0b2cf2a09d32abdedd17de864e93ad25
SHA1: 55615fa2582424e38705487d1d3969af8554f637
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-engbuild 003 Low
Vendor pom name XMP Library for Java High
Vendor pom artifactid xmpcore Low
Vendor pom url http://www.adobe.com/devnet/xmp.html Highest
Vendor Manifest implementation-minor 1 Low
Vendor pom groupid adobe.xmp Highest
Vendor pom groupid com.adobe.xmp Highest
Vendor Manifest Implementation-Vendor Copyright 2006-2009 Adobe Systems Incorporated. All rights reserved High
Vendor pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium
Vendor file name xmpcore High
Vendor Manifest implementation-micro 1 Low
Vendor Manifest builddate 2012 Jul 03 11:48:46-CEST Low
Vendor Manifest implementation-major 5 Low
Vendor central groupid com.adobe.xmp Highest
Product pom url http://www.adobe.com/devnet/xmp.html Medium
Product pom groupid adobe.xmp Low
Product Manifest implementation-engbuild 003 Low
Product central artifactid xmpcore Highest
Product pom name XMP Library for Java High
Product Manifest Implementation-Title Adobe XMP Core High
Product Manifest implementation-minor 1 Low
Product pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium
Product file name xmpcore High
Product Manifest implementation-micro 1 Low
Product Manifest builddate 2012 Jul 03 11:48:46-CEST Low
Product pom artifactid xmpcore Highest
Product Manifest implementation-major 5 Low
Version file version 5.1.2 Highest
Version central version 5.1.2 Highest
Version pom version 5.1.2 Highest
xercesImpl-2.9.1.jar
Description:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the
Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI),
a complete framework for building parser components and configurations that is extremely
modular and easy to program.
File Path: /home/ciagent/.m2/repository/xerces/xercesImpl/2.9.1/xercesImpl-2.9.1.jar
MD5: f807f86d7d9db25edbfc782aca7ca2a9
SHA1: 7bc7e49ddfe4fb5f193ed37ecc96c12292c8ceb6
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor manifest: org/apache/xerces/impl/Version.class Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium
Vendor file name xercesImpl High
Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium
Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom parent-groupid org.apache Medium
Vendor central groupid xerces Highest
Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom url http://xerces.apache.org/xerces2-j Highest
Vendor pom groupid xerces Highest
Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid xercesImpl Low
Vendor pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low
Vendor pom parent-artifactid apache Low
Vendor pom name Xerces2 Java Parser High
Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium
Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium
Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium
Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium
Product central artifactid xercesImpl Highest
Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium
Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium
Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium
Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium
Product pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low
Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium
Product pom artifactid xercesImpl Highest
Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium
Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium
Product pom parent-groupid org.apache Low
Product pom name Xerces2 Java Parser High
Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium
Product file name xercesImpl High
Product manifest: org/apache/xerces/impl/Version.class Implementation-Title org.apache.xerces.impl.Version Medium
Product pom url http://xerces.apache.org/xerces2-j Medium
Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium
Product pom groupid xerces Low
Product pom parent-artifactid apache Medium
Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium
Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium
Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium
Version pom version 2.9.1 Highest
Version central version 2.9.1 Highest
Version file version 2.9.1 Highest
Published Vulnerabilities
CVE-2012-0881 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Vulnerable Software & Versions:
metadata-extractor-2.6.2.jar
Description: Java library for reading metadata from image files.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/drewnoakes/metadata-extractor/2.6.2/metadata-extractor-2.6.2.jar
MD5: 8f3acbee87dbd5b0cdfacee3bb3aff8b
SHA1: 13930ff22d3f152bd969a63e88537d2f2adc2cd5
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid metadata-extractor Low
Vendor pom url http://code.google.com/p/metadata-extractor/ Highest
Vendor pom description Java library for reading metadata from image files. Medium
Vendor jar package name metadata Low
Vendor file name metadata-extractor High
Vendor pom groupid com.drewnoakes Highest
Vendor pom groupid drewnoakes Highest
Vendor pom name metadata-extractor High
Vendor jar package name drew Low
Vendor central groupid com.drewnoakes Highest
Product pom description Java library for reading metadata from image files. Medium
Product jar package name metadata Low
Product file name metadata-extractor High
Product central artifactid metadata-extractor Highest
Product pom url http://code.google.com/p/metadata-extractor/ Medium
Product pom name metadata-extractor High
Product pom artifactid metadata-extractor Highest
Product pom groupid drewnoakes Low
Version central version 2.6.2 Highest
Version pom version 2.6.2 Highest
Version file version 2.6.2 Highest
rome-1.0.jar
Description: All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it
easy to work in Java with most syndication formats. Today it accepts all flavors of RSS
(0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes
a set of parsers and generators for the various flavors of feeds, as well as converters
to convert from one format to another. The parsers can give you back Java objects that
are either specific for the format you want to work with, or a generic normalized
SyndFeed object that lets you work on with the data without bothering about the
underlying format.
File Path: /home/ciagent/.m2/repository/rome/rome/1.0/rome-1.0.jar
MD5: 53d38c030287b939f4e6d745ba1269a7
SHA1: 022b33347f315833e9348cec2751af1a5d5656e4
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization url http://java.sun.com/ Medium
Vendor Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low
Vendor Manifest embed-directory META-INF/lib Low
Vendor Manifest bundle-symbolicname rome.rome Medium
Vendor pom groupid rome Highest
Vendor file name rome High
Vendor pom name ROME, RSS and atOM utilitiEs for Java High
Vendor pom url https://rome.dev.java.net/ Highest
Vendor Manifest bundle-docurl http://java.sun.com/ Low
Vendor manifest Bundle-Description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Vendor pom artifactid rome Low
Vendor pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Vendor central groupid rome Highest
Vendor pom organization name Sun Microsystems High
Product pom organization url http://java.sun.com/ Low
Product central artifactid rome Highest
Product Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low
Product Manifest embed-directory META-INF/lib Low
Product Manifest bundle-symbolicname rome.rome Medium
Product file name rome High
Product Manifest Bundle-Name ROME, RSS and atOM utilitiEs for Java Medium
Product pom name ROME, RSS and atOM utilitiEs for Java High
Product Manifest bundle-docurl http://java.sun.com/ Low
Product manifest Bundle-Description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Product pom organization name Sun Microsystems Low
Product pom artifactid rome Highest
Product pom url https://rome.dev.java.net/ Medium
Product pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Product pom groupid rome Low
Version pom version 1.0 Highest
Version file version 1.0 Highest
Version central version 1.0 Highest
vorbis-java-core-0.1.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1.jar
MD5: b88115be2754cb6883e652ba68ca46c8
SHA1: 662a02b94701947e6e66e7793d996043f05fad4a
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom groupid org.gagravarr Highest
Vendor file name vorbis-java-core High
Vendor pom parent-groupid org.gagravarr Medium
Vendor central groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor pom artifactid vorbis-java-core Low
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor jar package name gagravarr Low
Vendor pom name Ogg and Vorbis for Java, Core High
Product pom url Gagravarr/VorbisJava High
Product central artifactid vorbis-java-core Highest
Product file name vorbis-java-core High
Product pom parent-groupid org.gagravarr Low
Product pom artifactid vorbis-java-core Highest
Product pom parent-artifactid vorbis-java-parent Medium
Product pom groupid gagravarr Low
Product pom name Ogg and Vorbis for Java, Core High
Version pom version 0.1 Highest
Version file version 0.1 Highest
Version central version 0.1 Highest
juniversalchardet-1.0.3.jar
Description: Java port of universalchardet
License:
Mozilla Public License 1.1 (MPL 1.1): http://www.mozilla.org/MPL/MPL-1.1.html
File Path: /home/ciagent/.m2/repository/com/googlecode/juniversalchardet/juniversalchardet/1.0.3/juniversalchardet-1.0.3.jar
MD5: d9ea0a9a275336c175b343f2e4cd8f27
SHA1: cd49678784c46aa8789c060538e0154013bb421b
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name juniversalchardet High
Vendor pom artifactid juniversalchardet Low
Vendor pom url http://juniversalchardet.googlecode.com/ Highest
Vendor central groupid com.googlecode.juniversalchardet High
Vendor jar package name prober Low
Vendor jar package name universalchardet Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom groupid googlecode.juniversalchardet Highest
Vendor pom description Java port of universalchardet Medium
Vendor pom groupid com.googlecode.juniversalchardet Highest
Vendor jar package name mozilla Low
Vendor file name juniversalchardet High
Product pom url http://juniversalchardet.googlecode.com/ Medium
Product pom artifactid juniversalchardet Highest
Product pom name juniversalchardet High
Product central artifactid juniversalchardet-1.0.3 High
Product pom description Java port of universalchardet Medium
Product jar package name prober Low
Product pom groupid googlecode.juniversalchardet Low
Product jar package name universalchardet Low
Product file name juniversalchardet High
Product central artifactid juniversalchardet High
Version pom version 1.0.3 Highest
Version file name juniversalchardet Medium
Version central version 1.0.3 High
Version file version 1.0.3 Highest
Version central version 2.0 High
jhighlight-1.0.jar
Description:
JHighlight is an embeddable pure Java syntax highlighting
library that supports Java, HTML, XHTML, XML and LZX
languages and outputs to XHTML.
It also supports RIFE templates tags and highlights them
clearly so that you can easily identify the difference
between your RIFE markup and the actual marked up source.
License:
CDDL, v1.0: http://www.opensource.org/licenses/cddl1.php
LGPL, v2.1 or later: http://www.opensource.org/licenses/lgpl-license.php
File Path: /home/ciagent/.m2/repository/com/uwyn/jhighlight/1.0/jhighlight-1.0.jar
MD5: 0ad5cf1bc56657f5e9e327e5e768da0a
SHA1: 0b1774029ee29472df8c25e5ba796431f7689fd6
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jhighlight Low
Vendor pom name JHighlight High
Vendor pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low
Vendor jar package name jhighlight Low
Vendor pom groupid com.uwyn Highest
Vendor pom organization name Uwyn High
Vendor file name jhighlight High
Vendor pom organization url http://uwyn.com/ Medium
Vendor pom groupid uwyn Highest
Vendor pom url https://jhighlight.dev.java.net/ Highest
Vendor central groupid com.uwyn Highest
Vendor jar package name uwyn Low
Product pom groupid uwyn Low
Product pom artifactid jhighlight Highest
Product pom name JHighlight High
Product pom organization name Uwyn Low
Product pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low
Product jar package name jhighlight Low
Product pom url https://jhighlight.dev.java.net/ Medium
Product pom organization url http://uwyn.com/ Low
Product central artifactid jhighlight Highest
Product file name jhighlight High
Version pom version 1.0 Highest
Version file version 1.0 Highest
Version central version 1.0 Highest
xmlbeans-2.6.0.jar
Description: XmlBeans main jar
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/xmlbeans/xmlbeans/2.6.0/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name XmlBeans High
Vendor pom artifactid xmlbeans Low
Vendor central groupid org.apache.xmlbeans Highest
Vendor pom groupid org.apache.xmlbeans Highest
Vendor pom organization name XmlBeans High
Vendor pom url http://xmlbeans.apache.org Highest
Vendor pom groupid apache.xmlbeans Highest
Vendor pom organization url http://xmlbeans.apache.org/ Medium
Vendor pom description XmlBeans main jar Medium
Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor Apache Software Foundation Medium
Vendor file name xmlbeans High
Product pom artifactid xmlbeans Highest
Product pom name XmlBeans High
Product manifest: org/apache/xmlbeans/ Implementation-Title org.apache.xmlbeans Medium
Product pom organization url http://xmlbeans.apache.org/ Low
Product pom url http://xmlbeans.apache.org Medium
Product pom description XmlBeans main jar Medium
Product pom organization name XmlBeans Low
Product central artifactid xmlbeans Highest
Product file name xmlbeans High
Product pom groupid apache.xmlbeans Low
Version file version 2.6.0 Highest
Version central version 2.6.0 Highest
Version pom version 2.6.0 Highest
exo.core.component.document-5.3.x-SNAPSHOT.jar
Description: Implementation of Document Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.document/5.3.x-SNAPSHOT/exo.core.component.document-5.3.x-SNAPSHOT.jar
MD5: f45710d396a164821cae9d6be2c43dea
SHA1: 3816bb2203bb3f7c818df5a3a3949a093bd74d02
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name eXo PLF Core :: Component :: Document Service High
Vendor pom groupid exoplatform.core Highest
Vendor pom description Implementation of Document Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom artifactid exo.core.component.document Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor file name exo.core.component.document High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.core Medium
Product pom name eXo PLF Core :: Component :: Document Service High
Product pom parent-artifactid core-parent Medium
Product pom description Implementation of Document Service of Exoplatform SAS 'eXo Core' project. Medium
Product file name exo.core.component.document High
Product pom artifactid exo.core.component.document Highest
Product pom groupid exoplatform.core Low
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: Document Service High
Version pom version 5.3.x-20190523.135914-2 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.document:5.3.x-SNAPSHOT
Confidence :High
exo.core.component.database-5.3.x-SNAPSHOT.jar
Description: Implementation of Database Service of Exoplatform SAS eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.database/5.3.x-SNAPSHOT/exo.core.component.database-5.3.x-SNAPSHOT.jar
MD5: 92c38f5d3a2df6c2b885ad7408b22678
SHA1: 5b5bff26d83127aa80f76883395a4db05c39a4ff
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.database Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor file name exo.core.component.database High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom name eXo PLF Core :: Component :: Database Service High
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Product Manifest Implementation-Title eXo PLF Core :: Component :: Database Service High
Product pom artifactid exo.core.component.database Highest
Product pom parent-artifactid core-parent Medium
Product file name exo.core.component.database High
Product pom groupid exoplatform.core Low
Product pom name eXo PLF Core :: Component :: Database Service High
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Product pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Version pom version 5.3.x-20190523.135858-2 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.database:5.3.x-SNAPSHOT
Confidence :High
lucene-core-3.6.2.jar
Description: Apache Lucene Java Core
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-core/3.6.2/lucene-core-3.6.2.jar
MD5: ee396d04f5a35557b424025f5382c815
SHA1: 9ec77e2507f9cc01756964c71d91efd8154a8c47
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid lucene-parent Low
Vendor pom description Apache Lucene Java Core Medium
Vendor pom name Lucene Core High
Vendor pom groupid org.apache.lucene Highest
Vendor pom parent-groupid org.apache.lucene Medium
Vendor pom artifactid lucene-core Low
Vendor central groupid org.apache.lucene Highest
Vendor file name lucene-core High
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom groupid apache.lucene Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom groupid apache.lucene Low
Product pom artifactid lucene-core Highest
Product pom description Apache Lucene Java Core Medium
Product file name lucene-core High
Product Manifest extension-name org.apache.lucene Medium
Product central artifactid lucene-core Highest
Product pom name Lucene Core High
Product Manifest Implementation-Title org.apache.lucene High
Product pom parent-groupid org.apache.lucene Low
Product pom parent-artifactid lucene-parent Medium
Product Manifest specification-title Lucene Search Engine: core Medium
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
Version file version 3.6.2 Highest
lucene-analyzers-3.6.2.jar
Description: Additional Analyzers
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-analyzers/3.6.2/lucene-analyzers-3.6.2.jar
MD5: 13f8241b6991bd1349c05369a7c0f002
SHA1: 3a083510dcb0d0fc67f8456cdac6f48aa0da2993
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid lucene-parent Low
Vendor pom artifactid lucene-analyzers Low
Vendor pom groupid org.apache.lucene Highest
Vendor pom parent-groupid org.apache.lucene Medium
Vendor central groupid org.apache.lucene Highest
Vendor file name lucene-analyzers High
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom groupid apache.lucene Highest
Vendor pom name Lucene Common Analyzers High
Vendor pom description Additional Analyzers Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom groupid apache.lucene Low
Product file name lucene-analyzers High
Product Manifest specification-title Lucene Search Engine: analyzers Medium
Product central artifactid lucene-analyzers Highest
Product Manifest extension-name org.apache.lucene Medium
Product pom name Lucene Common Analyzers High
Product pom artifactid lucene-analyzers Highest
Product Manifest Implementation-Title org.apache.lucene High
Product pom parent-groupid org.apache.lucene Low
Product pom parent-artifactid lucene-parent Medium
Product pom description Additional Analyzers Medium
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
Version file version 3.6.2 Highest
lucene-spellchecker-3.6.2.jar
Description: Spell Checker
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-spellchecker/3.6.2/lucene-spellchecker-3.6.2.jar
MD5: a4b684913f93aea76f5dbd7e479f19c5
SHA1: 15db0c0cfee44e275f15ad046e46b9a05910ad24
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid lucene-parent Low
Vendor pom groupid org.apache.lucene Highest
Vendor pom artifactid lucene-spellchecker Low
Vendor pom parent-groupid org.apache.lucene Medium
Vendor central groupid org.apache.lucene Highest
Vendor pom name Lucene Spellchecker High
Vendor file name lucene-spellchecker High
Vendor pom description Spell Checker Medium
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom groupid apache.lucene Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom name Lucene Spellchecker High
Product file name lucene-spellchecker High
Product Manifest specification-title Lucene Search Engine: spellchecker Medium
Product pom groupid apache.lucene Low
Product pom description Spell Checker Medium
Product central artifactid lucene-spellchecker Highest
Product Manifest extension-name org.apache.lucene Medium
Product Manifest Implementation-Title org.apache.lucene High
Product pom parent-groupid org.apache.lucene Low
Product pom parent-artifactid lucene-parent Medium
Product pom artifactid lucene-spellchecker Highest
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
Version file version 3.6.2 Highest
jta-1.1.jar
Description:
The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation.
File Path: /home/ciagent/.m2/repository/javax/transaction/jta/1.1/jta-1.1.jar
MD5: 82a10ce714f411b28f13850059de09ee
SHA1: 2ca09f0b36ca7d71b762e14ea2ff09d5eac57558
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest extension-name javax.transaction Medium
Vendor pom artifactid jta Low
Vendor pom description The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation. Low
Vendor pom groupid javax.transaction Highest
Vendor pom name Java Transaction API High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom url http://java.sun.com/products/jta Highest
Vendor file name jta High
Vendor central groupid javax.transaction High
Product Manifest extension-name javax.transaction Medium
Product pom description The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation. Low
Product central artifactid transaction-api High
Product Manifest specification-title Java Transaction API Specification Medium
Product pom name Java Transaction API High
Product pom url http://java.sun.com/products/jta Medium
Product central artifactid jta High
Product pom groupid javax.transaction Low
Product pom artifactid jta Highest
Product file name jta High
Version pom version 1.1 Highest
Version file version 1.1 Highest
Version central version 1.1 High
concurrent-1.3.4.jar
License:
Public domain, Sun Microsoystems: >http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html
File Path: /home/ciagent/.m2/repository/concurrent/concurrent/1.3.4/concurrent-1.3.4.jar
MD5: f29b9d930d3426ebc56919eba10fbd4d
SHA1: 1cf394c2a388199db550cda311174a4c6a7d117c
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization url http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html Medium
Vendor central groupid concurrent Highest
Vendor file name concurrent High
Vendor pom artifactid concurrent Low
Vendor jar package name cs Low
Vendor pom groupid concurrent Highest
Vendor pom name Dough Lea's util.concurrent package High
Vendor jar package name oswego Low
Vendor jar package name edu Low
Vendor pom organization name Dough Lea High
Product pom organization name Dough Lea Low
Product file name concurrent High
Product jar package name cs Low
Product central artifactid concurrent Highest
Product pom artifactid concurrent Highest
Product pom name Dough Lea's util.concurrent package High
Product pom organization url http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html Low
Product jar package name dl Low
Product jar package name oswego Low
Product pom groupid concurrent Low
Version central version 1.3.4 Highest
Version file version 1.3.4 Highest
Version pom version 1.3.4 Highest
commons-collections-3.2.2.jar
Description: Types that extend and augment the Java Collections Framework.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid commons-collections Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Vendor file name commons-collections High
Vendor pom url http://commons.apache.org/collections/ Highest
Vendor pom groupid commons-collections Highest
Vendor manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Vendor central groupid commons-collections Highest
Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium
Vendor Manifest implementation-url http://commons.apache.org/collections/ Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Vendor pom name Apache Commons Collections High
Vendor pom description Types that extend and augment the Java Collections Framework. Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product pom parent-artifactid commons-parent Medium
Product Manifest Implementation-Title Apache Commons Collections High
Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Product file name commons-collections High
Product pom parent-groupid org.apache.commons Low
Product pom groupid commons-collections Low
Product manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Product pom artifactid commons-collections Highest
Product Manifest bundle-symbolicname org.apache.commons.collections Medium
Product Manifest implementation-url http://commons.apache.org/collections/ Low
Product Manifest specification-title Apache Commons Collections Medium
Product Manifest bundle-docurl http://commons.apache.org/collections/ Low
Product pom url http://commons.apache.org/collections/ Medium
Product central artifactid commons-collections Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Product Manifest Bundle-Name Apache Commons Collections Medium
Product pom name Apache Commons Collections High
Product pom description Types that extend and augment the Java Collections Framework. Medium
Version central version 3.2.2 Highest
Version Manifest Implementation-Version 3.2.2 High
Version pom version 3.2.2 Highest
Version file version 3.2.2 Highest
jgroups-3.6.13.Final.jar
Description:
Reliable cluster communication toolkit
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/org/jgroups/jgroups/3.6.13.Final/jgroups-3.6.13.Final.jar
MD5: d7a4d1065e9b09e3f48bfa88ab368a0c
SHA1: 1315a8a1aed98dcafc11a850957ced42dc26bf18
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.jgroups.org Highest
Vendor pom groupid org.jgroups Highest
Vendor Manifest bundle-symbolicname org.jgroups Medium
Vendor pom groupid jgroups Highest
Vendor pom description
Reliable cluster communication toolkit
Medium
Vendor file name jgroups High
Vendor central groupid org.jgroups Highest
Vendor pom organization url http://www.jboss.org Medium
Vendor manifest Bundle-Description Ant/ivy based build.xml file for JGroups. Needs ant to run Medium
Vendor pom artifactid jgroups Low
Vendor pom organization name JBoss, a division of Red Hat High
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom name JGroups High
Product pom organization name JBoss, a division of Red Hat Low
Product Manifest bundle-symbolicname org.jgroups Medium
Product pom description
Reliable cluster communication toolkit
Medium
Product file name jgroups High
Product pom url http://www.jgroups.org Medium
Product pom artifactid jgroups Highest
Product pom groupid jgroups Low
Product manifest Bundle-Description Ant/ivy based build.xml file for JGroups. Needs ant to run Medium
Product central artifactid jgroups Highest
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest bundle-docurl http://www.jboss.org Low
Product pom organization url http://www.jboss.org Low
Product Manifest Bundle-Name JGroups Medium
Product pom name JGroups High
Version pom version 3.6.13.Final Highest
Version Manifest Implementation-Version 3.6.13.Final High
Version central version 3.6.13.Final Highest
Version file version 3.6.13 Highest
jbossjta-4.16.6.Final.jar
Description: JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA)
License:
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/jboss/jbossts/jbossjta/4.16.6.Final/jbossjta-4.16.6.Final.jar
MD5: 9e3c8d7d93b92ab97489aeb5816370c8
SHA1: 99e79e03ced180bea4e3307511d350eb2b88c91c
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JBossTS jbossjta High
Vendor pom description JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA) Medium
Vendor Manifest arjuna-properties-file jbossts-properties.xml Low
Vendor pom url http://www.jboss.org/jbosstm/ Highest
Vendor central groupid org.jboss.jbossts Highest
Vendor Manifest arjuna-builder JBoss Inc. [tom] Linux 3.4.11-1.fc16.x86_64 2012/Oct/02 15:05 Low
Vendor pom groupid org.jboss.jbossts Highest
Vendor pom artifactid jbossjta Low
Vendor file name jbossjta High
Vendor pom groupid jboss.jbossts Highest
Product pom name JBossTS jbossjta High
Product pom description JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA) Medium
Product Manifest arjuna-properties-file jbossts-properties.xml Low
Product pom groupid jboss.jbossts Low
Product pom artifactid jbossjta Highest
Product Manifest arjuna-builder JBoss Inc. [tom] Linux 3.4.11-1.fc16.x86_64 2012/Oct/02 15:05 Low
Product pom url http://www.jboss.org/jbosstm/ Medium
Product file name jbossjta High
Product central artifactid jbossjta Highest
Version pom version 4.16.6.Final Highest
Version file version 4.16.6 Highest
Version central version 4.16.6.Final Highest
ws-commons-util-1.0.1.jar
Description: This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/ws/commons/ws-commons-util/1.0.1/ws-commons-util-1.0.1.jar
MD5: 66919d22287ddab742a135da764c2cd6
SHA1: 126e80ff798fece634bc94e61f8be8a8da00be60
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://ws.apache.org/commons/util Highest
Vendor Manifest extension-name ws-commons-util Medium
Vendor pom groupid apache.ws.commons Highest
Vendor pom artifactid ws-commons-util Low
Vendor file name ws-commons-util High
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom name Apache WebServices Common Utilities High
Vendor central groupid ws-commons-util High
Vendor pom description This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Low
Vendor pom groupid org.apache.ws.commons Highest
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://www.apache.org/ Medium
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor central groupid org.apache.ws.commons High
Product Manifest extension-name ws-commons-util Medium
Product file name ws-commons-util High
Product pom name Apache WebServices Common Utilities High
Product pom url http://ws.apache.org/commons/util Medium
Product Manifest specification-title This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Medium
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom description This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Low
Product central artifactid ws-commons-util High
Product Manifest Implementation-Title ws-commons-util High
Product pom groupid apache.ws.commons Low
Product pom artifactid ws-commons-util Highest
Version file version 1.0.1 Highest
Version central version 1.0.1 High
Version Manifest Implementation-Version 1.0.1 High
Version pom version 1.0.1 Highest
Published Vulnerabilities
CVE-2016-10542 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.
Vulnerable Software & Versions:
jboss-common-core-2.2.22.GA.jar
Description: JBoss Common Core Utility classes
File Path: /home/ciagent/.m2/repository/org/jboss/jboss-common-core/2.2.22.GA/jboss-common-core-2.2.22.GA.jar
MD5: 8c415e1467075a90045a7b0fd19886a3
SHA1: ae1a22412d879c4ac48e35cf00f438bb263d41c3
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor JBoss, a division of Red Hat, Inc. Low
Vendor pom groupid org.jboss Highest
Vendor Manifest Implementation-Vendor JBoss, a division of Red Hat, Inc. High
Vendor central groupid org.jboss Highest
Vendor file name jboss-common-core High
Vendor pom parent-artifactid jboss-parent Low
Vendor pom name JBoss Common Classes High
Vendor pom url http://www.jboss.org/jboss-common Highest
Vendor pom description JBoss Common Core Utility classes Medium
Vendor Manifest implementation-url http://www.jboss.org/jboss-common Low
Vendor pom artifactid jboss-common-core Low
Vendor pom parent-groupid org.jboss Medium
Vendor pom groupid jboss Highest
Vendor Manifest Implementation-Vendor-Id org.jboss Medium
Product Manifest Implementation-Title JBoss Common Classes High
Product file name jboss-common-core High
Product central artifactid jboss-common-core Highest
Product pom name JBoss Common Classes High
Product pom groupid jboss Low
Product pom description JBoss Common Core Utility classes Medium
Product Manifest implementation-url http://www.jboss.org/jboss-common Low
Product pom parent-groupid org.jboss Low
Product pom url http://www.jboss.org/jboss-common Medium
Product pom parent-artifactid jboss-parent Medium
Product pom artifactid jboss-common-core Highest
Product Manifest specification-title JBoss Common Classes Medium
Version pom version 2.2.22.GA Highest
Version central version 2.2.22.GA Highest
Version file version 2.2.22 Highest
Version Manifest Implementation-Version 2.2.22.GA High
stringtemplate-3.2.1.jar
Description: StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output.
StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization.
It evolved over years of effort developing jGuru.com.
StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic
is that unlike other engines, it strictly enforces model-view separation.
Strict separation makes websites and code generators more flexible
and maintainable; it also provides an excellent defense against malicious
template authors.
There are currently about 600 StringTemplate source downloads a month.
License:
BSD licence: http://antlr.org/license.html
File Path: /home/ciagent/.m2/repository/org/antlr/stringtemplate/3.2.1/stringtemplate-3.2.1.jar
MD5: b58ca53e518a92a1991eb63b61917582
SHA1: 59ec8083721eae215c6f3caee944c410d2be34de
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.antlr Highest
Vendor pom groupid antlr Highest
Vendor jar package name stringtemplate Low
Vendor jar package name language Low
Vendor file name stringtemplate High
Vendor pom url http://www.stringtemplate.org Highest
Vendor jar package name antlr Low
Vendor central groupid org.antlr Highest
Vendor pom description StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output. StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization. It evolved over years of effort developing jGuru.com. StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic is that un... Low
Vendor pom name ANTLR StringTemplate High
Vendor pom artifactid stringtemplate Low
Product jar package name language Low
Product jar package name stringtemplate Low
Product file name stringtemplate High
Product pom url http://www.stringtemplate.org Medium
Product pom description StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output. StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization. It evolved over years of effort developing jGuru.com. StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic is that un... Low
Product pom artifactid stringtemplate Highest
Product pom name ANTLR StringTemplate High
Product pom groupid antlr Low
Product central artifactid stringtemplate Highest
Version pom version 3.2.1 Highest
Version central version 3.2.1 Highest
Version file version 3.2.1 Highest
antlr-runtime-3.5.jar
Description: A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions.
File Path: /home/ciagent/.m2/repository/org/antlr/antlr-runtime/3.5/antlr-runtime-3.5.jar
MD5: aa6d7c8b425df59f5f5bc98c58cfd9fc
SHA1: 0baa82bff19059401e90e1b90020beb9c96305d7
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.antlr Highest
Vendor central groupid org.antlr Highest
Vendor Manifest Implementation-Vendor-Id org.antlr Medium
Vendor pom name ANTLR 3 Runtime High
Vendor file name antlr-runtime High
Vendor pom groupid antlr Highest
Vendor pom parent-groupid org.antlr Medium
Vendor pom url http://www.antlr.org Highest
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor Manifest Implementation-Vendor ANTLR High
Vendor pom parent-artifactid antlr-master Low
Vendor pom artifactid antlr-runtime Low
Product pom parent-artifactid antlr-master Medium
Product pom artifactid antlr-runtime Highest
Product pom name ANTLR 3 Runtime High
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom url http://www.antlr.org Medium
Product central artifactid antlr-runtime Highest
Product file name antlr-runtime High
Product pom groupid antlr Low
Product Manifest Implementation-Title ANTLR 3 Runtime High
Product pom parent-groupid org.antlr Low
Version pom version 3.5 Highest
Version Manifest Implementation-Version 3.5 High
Version central version 3.5 Highest
Version file version 3.5 Highest
exo.kernel.component.ext.cache.impl.infinispan.v8-5.3.x-SNAPSHOT.jar
Description: Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.ext.cache.impl.infinispan.v8/5.3.x-SNAPSHOT/exo.kernel.component.ext.cache.impl.infinispan.v8-5.3.x-SNAPSHOT.jar
MD5: 2bd82588a1d04ea435de3b334321abb1
SHA1: 1008ebec01e1a674843d64dee25fdd0daf31078e
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Low
Vendor file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Vendor pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Product Manifest specification-title exo-kernel Medium
Product file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Product pom groupid exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Product pom parent-artifactid kernel-parent Medium
Product pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Product pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Highest
Product Manifest Implementation-Title eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Product pom parent-groupid org.exoplatform.kernel Low
Version pom version 5.3.x-20190523.135435-2 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.ext.cache.impl.infinispan.v8:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:infinispan:infinispan:5.3.0
Confidence :Highest
suppress
Published Vulnerabilities
CVE-2016-0750 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-15089 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-2638 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-287 Improper Authentication
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Vulnerable Software & Versions: (show all )
jboss-marshalling-osgi-2.0.0.Beta3.jar
Description: JBoss Marshalling OSGi Bundle with API and implementations
License:
http://repository.jboss.org/licenses/cc0-1.0.txt
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar
MD5: 7652392087f6e70312cf0309ab563a4f
SHA1: a55fe6527a2d50dc48ad3f8b9093bd0cb01302b0
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.jboss.marshalling.jboss-marshalling-osgi Medium
Vendor jar package name jboss Low
Vendor central groupid org.jboss.marshalling Highest
Vendor file name jboss-marshalling-osgi High
Vendor Manifest Implementation-Vendor-Id org.jboss.marshalling Medium
Vendor pom groupid org.jboss.marshalling Highest
Vendor manifest Bundle-Description JBoss Marshalling OSGi Bundle with API and implementations Medium
Vendor Manifest bundle-docurl http://jboss.org/jbossmarshalling Low
Vendor Manifest implementation-url http://www.jboss.org/jboss-marshalling-parent/jboss-marshalling-osgi Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor jar package name marshalling Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest os-name Linux Medium
Product Manifest bundle-symbolicname org.jboss.marshalling.jboss-marshalling-osgi Medium
Product Manifest Bundle-Name JBoss Marshalling OSGi Bundle Medium
Product file name jboss-marshalling-osgi High
Product Manifest specification-title JBoss Marshalling OSGi Bundle Medium
Product Manifest Implementation-Title JBoss Marshalling OSGi Bundle High
Product manifest Bundle-Description JBoss Marshalling OSGi Bundle with API and implementations Medium
Product Manifest bundle-docurl http://jboss.org/jbossmarshalling Low
Product pom artifactid jboss-marshalling-osgi Highest
Product Manifest implementation-url http://www.jboss.org/jboss-marshalling-parent/jboss-marshalling-osgi Low
Product jar package name marshalling Low
Product central artifactid jboss-marshalling-osgi Highest
Product Manifest os-name Linux Medium
Version pom version 2.0.0.Beta3 Highest
Version central version 2.0.0.Beta3 Highest
Version Manifest Implementation-Version 2.0.0.Beta3 High
infinispan-core-8.2.6.Final.jar
Description: Infinispan core module
License:
http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/org/infinispan/infinispan-core/8.2.6.Final/infinispan-core-8.2.6.Final.jar
MD5: 06371c22b39aef4faf1da8d21b2102cb
SHA1: 84937a866a56760b9c50bfbca10442fa14be6375
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Infinispan core module Medium
Vendor central groupid org.infinispan Highest
Vendor pom groupid org.infinispan Highest
Vendor Manifest bundle-symbolicname org.infinispan.core Medium
Vendor pom artifactid infinispan-core Low
Vendor Manifest bundle-blueprint OSGI-INF/blueprint/blueprint.xml Low
Vendor pom parent-artifactid infinispan-parent Low
Vendor Manifest specification-vendor JBoss, a division of Red Hat Low
Vendor file name infinispan-core High
Vendor pom groupid infinispan Highest
Vendor manifest Bundle-Description Infinispan core module Medium
Vendor pom name Infinispan Core High
Vendor Manifest Implementation-Vendor JBoss, a division of Red Hat High
Vendor Manifest bundle-docurl http://www.infinispan.org/ Low
Vendor pom parent-groupid org.infinispan Medium
Vendor Manifest Implementation-Vendor-Id org.infinispan Medium
Product pom description Infinispan core module Medium
Product Manifest bundle-symbolicname org.infinispan.core Medium
Product Manifest specification-title Infinispan Core Medium
Product Manifest bundle-blueprint OSGI-INF/blueprint/blueprint.xml Low
Product file name infinispan-core High
Product manifest Bundle-Description Infinispan core module Medium
Product pom parent-groupid org.infinispan Low
Product pom parent-artifactid infinispan-parent Medium
Product pom name Infinispan Core High
Product Manifest bundle-docurl http://www.infinispan.org/ Low
Product pom groupid infinispan Low
Product pom artifactid infinispan-core Highest
Product Manifest Implementation-Title Infinispan Core High
Product central artifactid infinispan-core Highest
Product Manifest Bundle-Name Infinispan Core Medium
Version pom version 8.2.6.Final Highest
Version Manifest Implementation-Version 8.2.6.Final High
Version central version 8.2.6.Final Highest
Version file version 8.2.6 Highest
Related Dependencies
infinispan-cachestore-jdbc-8.2.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/infinispan/infinispan-cachestore-jdbc/8.2.6.Final/infinispan-cachestore-jdbc-8.2.6.Final.jar
SHA1: 1703f2cae7b2cb483158dca831d68ee711f301ab
MD5: 3ca2e9d4e5ed44fc984fe94c2d943bf2
cpe: cpe:/a:infinispan:infinispan:8.2.6
maven: org.infinispan:infinispan-cachestore-jdbc:8.2.6.Final ✓
Published Vulnerabilities
CVE-2016-0750 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-15089 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-2638 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-287 Improper Authentication
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Vulnerable Software & Versions: (show all )
exo.jcr.component.core-5.3.x-SNAPSHOT.jar
Description: Implementation of Core Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.core/5.3.x-SNAPSHOT/exo.jcr.component.core-5.3.x-SNAPSHOT.jar
MD5: 270fed54370dddb7b6f2a0ac0a53fb19
SHA1: 2e610d06ecc8ae00c94f7504cdef11211515dbd3
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.jcr.component.core High
Vendor pom groupid org.exoplatform.jcr Highest
Vendor pom groupid exoplatform.jcr Highest
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor pom name eXo PLF:: JCR :: Component :: Core Service High
Vendor pom description Implementation of Core Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid exo.jcr.component.core Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid jcr-parent Low
Product file name exo.jcr.component.core High
Product pom parent-groupid org.exoplatform.jcr Low
Product pom name eXo PLF:: JCR :: Component :: Core Service High
Product pom description Implementation of Core Service of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest specification-title exo-jcr Medium
Product pom parent-artifactid jcr-parent Medium
Product pom artifactid exo.jcr.component.core Highest
Product pom groupid exoplatform.jcr Low
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Core Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.core:5.3.x-SNAPSHOT
Confidence :High
jtidy-r938.jar
Description:
JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be
used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the
document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML.
License:
Java HTML Tidy License: http://jtidy.svn.sourceforge.net/viewvc/jtidy/trunk/jtidy/LICENSE.txt?revision=95
File Path: /home/ciagent/.m2/repository/net/sf/jtidy/jtidy/r938/jtidy-r938.jar
MD5: 6a9121561b8f98c0a8fb9b6e57f50e6b
SHA1: ab08d87a225a715a69107732b67f21e1da930349
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JTidy High
Vendor pom url http://jtidy.sourceforge.net Highest
Vendor central groupid net.sf.jtidy Highest
Vendor pom organization url http://sourceforge.net Medium
Vendor jar package name tidy Low
Vendor pom organization name sourceforge High
Vendor pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Vendor pom groupid net.sf.jtidy Highest
Vendor file name jtidy-r938 High
Vendor pom artifactid jtidy Low
Vendor jar package name w3c Low
Product pom artifactid jtidy Highest
Product pom name JTidy High
Product jar package name tidy Low
Product pom organization url http://sourceforge.net Low
Product pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Product pom groupid net.sf.jtidy Low
Product pom url http://jtidy.sourceforge.net Medium
Product file name jtidy-r938 High
Product pom organization name sourceforge Low
Product central artifactid jtidy Highest
Version file name jtidy-r938 Medium
Version pom version r938 Highest
Version file version 938 Medium
Version central version r938 Highest
exo.core.component.xml-processing-5.3.x-SNAPSHOT.jar
Description: Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.xml-processing/5.3.x-SNAPSHOT/exo.core.component.xml-processing-5.3.x-SNAPSHOT.jar
MD5: 72733f679e354536825490dcd09a699a
SHA1: 8abf87f511ed36fa29ee72cd75c7308f852c7b6f
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.xml-processing Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF Core :: Component :: XML Processing Service High
Vendor pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor file name exo.core.component.xml-processing High
Vendor pom parent-groupid org.exoplatform.core Medium
Product pom parent-artifactid core-parent Medium
Product pom artifactid exo.core.component.xml-processing Highest
Product pom groupid exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: XML Processing Service High
Product pom name eXo PLF Core :: Component :: XML Processing Service High
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Product pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Product file name exo.core.component.xml-processing High
Version pom version 5.3.x-20190523.135957-2 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
cpe: cpe:/a:processing:processing:5.3.20190523
Confidence :Low
suppress
maven: org.exoplatform.core:exo.core.component.xml-processing:5.3.x-SNAPSHOT
Confidence :High
exo.core.component.script.groovy-5.3.x-SNAPSHOT.jar
Description: Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.script.groovy/5.3.x-SNAPSHOT/exo.core.component.script.groovy-5.3.x-SNAPSHOT.jar
MD5: 7b83e6a1b4a6dad0afeeb2169f8bed89
SHA1: ee331e349386b130980f5564f3ba15a9cba7ebce
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.script.groovy Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor file name exo.core.component.script.groovy High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid core-parent Low
Vendor pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Vendor pom parent-groupid org.exoplatform.core Medium
Product pom parent-artifactid core-parent Medium
Product file name exo.core.component.script.groovy High
Product pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Product pom groupid exoplatform.core Low
Product pom artifactid exo.core.component.script.groovy Highest
Product Manifest Implementation-Title eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Product pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Product Manifest specification-title exo-core Medium
Product pom parent-groupid org.exoplatform.core Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.script.groovy:5.3.x-SNAPSHOT
Confidence :High
jsr250-api-1.0.jar
Description: JSR-250 Reference Implementation by Glassfish
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest
Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High
Vendor pom description JSR-250 Reference Implementation by Glassfish Medium
Vendor central groupid javax.annotation Highest
Vendor pom groupid javax.annotation Highest
Vendor pom artifactid jsr250-api Low
Vendor jar package name javax Low
Vendor jar package name annotation Low
Vendor file name jsr250-api High
Product pom name JSR-250 Common Annotations for the JavaTM Platform High
Product pom description JSR-250 Reference Implementation by Glassfish Medium
Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium
Product central artifactid jsr250-api Highest
Product pom groupid javax.annotation Low
Product jar package name annotation Low
Product file name jsr250-api High
Product pom artifactid jsr250-api Highest
Version pom version 1.0 Highest
Version file version 1.0 Highest
Version central version 1.0 Highest
exo.jcr.component.ext-5.3.x-SNAPSHOT.jar
Description: Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.ext/5.3.x-SNAPSHOT/exo.jcr.component.ext-5.3.x-SNAPSHOT.jar
MD5: 80ba6722d208fa7b15b8c7d090d4c0cc
SHA1: ecd82797b6732d7e1c33328f5970ffd1d7caee03
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.jcr Highest
Vendor pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Vendor pom groupid exoplatform.jcr Highest
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor file name exo.jcr.component.ext High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF:: JCR :: Component :: Extension Service High
Vendor pom artifactid exo.jcr.component.ext Low
Vendor pom parent-artifactid jcr-parent Low
Product pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Product pom parent-groupid org.exoplatform.jcr Low
Product pom artifactid exo.jcr.component.ext Highest
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Extension Service High
Product Manifest specification-title exo-jcr Medium
Product pom parent-artifactid jcr-parent Medium
Product file name exo.jcr.component.ext High
Product pom groupid exoplatform.jcr Low
Product pom name eXo PLF:: JCR :: Component :: Extension Service High
Version pom version 5.3.x-20190523.150002-3 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.ext:5.3.x-SNAPSHOT
Confidence :High
mime-util-2.1.3.jar
Description: mime-util is a simple to use, small, light weight and fast open source java utility library that can detect
MIME types from files, input streams, URL's and byte arrays.
Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/eu/medsea/mimeutil/mime-util/2.1.3/mime-util-2.1.3.jar
MD5: 3d4f3e1a96eb79683197f1c8b182f4a6
SHA1: 0c9cfae15c74f62491d4f28def0dff1dabe52a47
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest url http://www.medsea.eu/mime-util/ Low
Vendor pom name Mime Detection Utility High
Vendor manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor file name mime-util High
Vendor pom url http://www.medsea.eu/mime-util/ Highest
Vendor Manifest bundle-docurl http://www.medsea.eu Low
Vendor central groupid eu.medsea.mimeutil Highest
Vendor pom organization name Medsea Business Solutions S.L. High
Vendor pom artifactid mime-util Low
Vendor pom groupid eu.medsea.mimeutil Highest
Vendor pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor pom organization url http://www.medsea.eu Medium
Vendor Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Product pom artifactid mime-util Highest
Product Manifest url http://www.medsea.eu/mime-util/ Low
Product Manifest Bundle-Name Mime Detection Utility Medium
Product pom name Mime Detection Utility High
Product central artifactid mime-util Highest
Product manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Product file name mime-util High
Product Manifest bundle-docurl http://www.medsea.eu Low
Product pom organization url http://www.medsea.eu Low
Product pom url http://www.medsea.eu/mime-util/ Medium
Product pom groupid eu.medsea.mimeutil Low
Product pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Product Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Product pom organization name Medsea Business Solutions S.L. Low
Version pom version 2.1.3 Highest
Version central version 2.1.3 Highest
Version file version 2.1.3 Highest
slf4j-api-1.7.18.jar
Description: The slf4j API
File Path: /home/ciagent/.m2/repository/org/slf4j/slf4j-api/1.7.18/slf4j-api-1.7.18.jar
MD5: 1b1d1af21206ac5ae44cd79a6c04dd92
SHA1: b631d286463ced7cc42ee2171fe3beaed2836823
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom name SLF4J API Module High
Vendor pom groupid slf4j Highest
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor pom artifactid slf4j-api Low
Vendor pom description The slf4j API Medium
Vendor central groupid org.slf4j Highest
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom groupid org.slf4j Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom parent-groupid org.slf4j Medium
Vendor file name slf4j-api High
Vendor manifest Bundle-Description The slf4j API Medium
Vendor pom url http://www.slf4j.org Highest
Product pom name SLF4J API Module High
Product pom parent-groupid org.slf4j Low
Product pom artifactid slf4j-api Highest
Product Manifest bundle-symbolicname slf4j.api Medium
Product pom groupid slf4j Low
Product central artifactid slf4j-api Highest
Product Manifest Bundle-Name slf4j-api Medium
Product pom description The slf4j API Medium
Product Manifest Implementation-Title slf4j-api High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product file name slf4j-api High
Product manifest Bundle-Description The slf4j API Medium
Version file version 1.7.18 Highest
Version central version 1.7.18 Highest
Version Manifest Implementation-Version 1.7.18 High
Version pom version 1.7.18 Highest
exo.kernel.commons-5.3.x-SNAPSHOT.jar
Description: Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.commons/5.3.x-SNAPSHOT/exo.kernel.commons-5.3.x-SNAPSHOT.jar
MD5: e45922985af7344ecbcca4bae3fc09ab
SHA1: c338e8e2fb4598959349acdf407306be46246113
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.kernel.commons High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom name eXo PLF:: Kernel :: Commons Utils High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom artifactid exo.kernel.commons Low
Vendor pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Product file name exo.kernel.commons High
Product pom name eXo PLF:: Kernel :: Commons Utils High
Product Manifest specification-title exo-kernel Medium
Product pom artifactid exo.kernel.commons Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Commons Utils High
Product pom parent-groupid org.exoplatform.kernel Low
Product pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.commons:5.3.x-SNAPSHOT
Confidence :High
commons-beanutils-1.8.3.jar
Description: BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-beanutils/commons-beanutils/1.8.3/commons-beanutils-1.8.3.jar
MD5: b45be74134796c89db7126083129532f
SHA1: 686ef3410bcf4ab8ce7fd0b899e832aaba5facf7
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name commons-beanutils High
Vendor pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Vendor pom url http://commons.apache.org/beanutils/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom groupid commons-beanutils Highest
Vendor Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Vendor pom name Commons BeanUtils High
Vendor pom artifactid commons-beanutils Low
Vendor manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid commons-beanutils Highest
Vendor Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product file name commons-beanutils High
Product pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product Manifest Bundle-Name Commons BeanUtils Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Product pom name Commons BeanUtils High
Product pom url http://commons.apache.org/beanutils/ Medium
Product pom parent-groupid org.apache.commons Low
Product manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product central artifactid commons-beanutils Highest
Product pom groupid commons-beanutils Low
Product Manifest Implementation-Title Commons BeanUtils High
Product pom artifactid commons-beanutils Highest
Product Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Product Manifest specification-title Commons BeanUtils Medium
Version pom version 1.8.3 Highest
Version central version 1.8.3 Highest
Version file version 1.8.3 Highest
Version Manifest Implementation-Version 1.8.3 High
Published Vulnerabilities
CVE-2014-0114 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
Vulnerable Software & Versions: (show all )
common-common-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-common/2.2.2.Final/common-common-2.2.2.Final.jar
MD5: 8ce16b5e3991285cd27e553740d09d1f
SHA1: 44522d899e31a5a10dbd70f7b0ca2fe5a614f740
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor file name common-common High
Vendor pom artifactid common-common Low
Vendor central groupid org.gatein.common Highest
Vendor pom parent-artifactid common-parent Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom groupid org.gatein.common Highest
Vendor pom parent-groupid org.gatein.common Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid gatein.common Highest
Vendor Manifest os-name Linux Medium
Vendor pom name GateIn - Common component (common) High
Vendor Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product pom groupid gatein.common Low
Product Manifest Implementation-Title GateIn - Common component (common) High
Product file name common-common High
Product pom parent-groupid org.gatein.common Low
Product Manifest specification-title GateIn - Common component (common) Medium
Product central artifactid common-common Highest
Product pom artifactid common-common Highest
Product Manifest os-name Linux Medium
Product pom name GateIn - Common component (common) High
Product Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Product pom parent-artifactid common-parent Medium
Version Manifest Implementation-Version 2.2.2.Final High
Version central version 2.2.2.Final Highest
Version pom version 2.2.2.Final Highest
Version file version 2.2.2 Highest
wci-wci-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/wci/wci-wci/5.3.x-SNAPSHOT/wci-wci-5.3.x-SNAPSHOT.jar
MD5: 2ab001252fa543ff2b30839d5d8b60ec
SHA1: 70f414374362f77fa7ec7a35797e32395bbf36ee
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.gatein.wci Highest
Vendor pom parent-groupid org.exoplatform.gatein.wci Medium
Vendor Manifest build-timestamp Thu, 23 May 2019 09:57:20 +0000 Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.wci Medium
Vendor pom name GateIn - Web Container Integration component (wci) High
Vendor pom parent-artifactid wci-parent Low
Vendor pom groupid org.exoplatform.gatein.wci Highest
Vendor file name wci-wci High
Vendor Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Vendor pom artifactid wci-wci Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest os-name Linux Medium
Product pom parent-groupid org.exoplatform.gatein.wci Low
Product file name wci-wci High
Product Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Product Manifest Implementation-Title GateIn - Web Container Integration component (wci) High
Product Manifest specification-title GateIn - Web Container Integration component (wci) Medium
Product pom groupid exoplatform.gatein.wci Low
Product Manifest build-timestamp Thu, 23 May 2019 09:57:20 +0000 Low
Product pom artifactid wci-wci Highest
Product pom name GateIn - Web Container Integration component (wci) High
Product pom parent-artifactid wci-parent Medium
Product Manifest os-name Linux Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.wci:wci-wci:5.3.x-SNAPSHOT
Confidence :High
jibx-run-1.2.6.jar
Description: JiBX runtime code
License:
http://jibx.sourceforge.net/jibx-license.html
File Path: /home/ciagent/.m2/repository/org/jibx/jibx-run/1.2.6/jibx-run-1.2.6.jar
MD5: 4ef53e4279c8440aff2d16c0af024231
SHA1: 544f3ac7887d7eed20ca0420ee1963df6c7ecebb
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname jibx-run Medium
Vendor central groupid org.jibx Highest
Vendor pom artifactid jibx-run Low
Vendor pom groupid org.jibx Highest
Vendor pom parent-artifactid main-reactor Low
Vendor pom description JiBX runtime code Medium
Vendor Manifest bundle-docurl http://www.jibx.org Low
Vendor file name jibx-run High
Vendor pom groupid jibx Highest
Vendor pom name jibx-run - JiBX runtime High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor manifest Bundle-Description JiBX runtime code Medium
Vendor pom parent-groupid org.jibx.config Medium
Product Manifest bundle-symbolicname jibx-run Medium
Product Manifest Bundle-Name jibx-run - JiBX runtime Medium
Product pom parent-artifactid main-reactor Medium
Product pom description JiBX runtime code Medium
Product Manifest bundle-docurl http://www.jibx.org Low
Product pom parent-groupid org.jibx.config Low
Product file name jibx-run High
Product pom name jibx-run - JiBX runtime High
Product pom artifactid jibx-run Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product manifest Bundle-Description JiBX runtime code Medium
Product central artifactid jibx-run Highest
Product pom groupid jibx Low
Version central version 1.2.6 Highest
Version file version 1.2.6 Highest
Version pom version 1.2.6 Highest
javax.inject-1.jar
Description: The javax.inject API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description The javax.inject API Medium
Vendor pom url http://code.google.com/p/atinject/ Highest
Vendor pom artifactid javax.inject Low
Vendor central groupid javax.inject Highest
Vendor pom name javax.inject High
Vendor jar package name inject Low
Vendor jar package name javax Low
Vendor pom groupid javax.inject Highest
Vendor file name javax.inject-1 High
Product pom description The javax.inject API Medium
Product pom artifactid javax.inject Highest
Product pom name javax.inject High
Product jar package name inject Low
Product pom url http://code.google.com/p/atinject/ Medium
Product file name javax.inject-1 High
Product central artifactid javax.inject Highest
Product pom groupid javax.inject Low
Version central version 1 Highest
Version file version 1 Medium
Version pom version 1 Highest
cdi-api-1.0-SP4.jar
Description: APIs for JSR-299: Contexts and Dependency Injection for Java EE
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/javax/enterprise/cdi-api/1.0-SP4/cdi-api-1.0-SP4.jar
MD5: 6c1e2b4036d64b6ba1a1136a00c7cdaa
SHA1: 6e38490033eb8b36c4cf1f7605163424a574dcf0
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid cdi-api Low
Vendor central groupid javax.enterprise Highest
Vendor pom parent-groupid org.jboss.weld Medium
Vendor pom url http://www.seamframework.org/Weld Highest
Vendor pom groupid javax.enterprise Highest
Vendor file name cdi-api High
Vendor pom name CDI APIs High
Vendor pom parent-artifactid weld-parent Low
Vendor pom organization url http://seamframework.org Medium
Vendor pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Vendor Manifest Implementation-Vendor Seam Framework High
Vendor Manifest implementation-url http://www.seamframework.org/Weld Low
Vendor pom organization name Seam Framework High
Vendor Manifest specification-vendor Seam Framework Low
Product Manifest specification-title CDI APIs Medium
Product pom parent-groupid org.jboss.weld Low
Product file name cdi-api High
Product pom name CDI APIs High
Product pom groupid javax.enterprise Low
Product pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Product Manifest implementation-url http://www.seamframework.org/Weld Low
Product pom artifactid cdi-api Highest
Product pom parent-artifactid weld-parent Medium
Product Manifest Implementation-Title CDI APIs High
Product pom organization url http://seamframework.org Low
Product central artifactid cdi-api Highest
Product pom url http://www.seamframework.org/Weld Medium
Product pom organization name Seam Framework Low
Version file version 1.0.sp4 Highest
Version pom version 1.0-SP4 Highest
Version central version 1.0-SP4 Highest
exo.kernel.container-5.3.x-SNAPSHOT.jar
Description: Implementation of Container for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.container/5.3.x-SNAPSHOT/exo.kernel.container-5.3.x-SNAPSHOT.jar
MD5: e3a9fd28ca075c2222bbeed39e55297d
SHA1: 6a171b6b0e06e09151f08de470d69b3b5358489a
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.container Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom name eXo PLF:: Kernel :: Container High
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor file name exo.kernel.container High
Vendor pom groupid exoplatform.kernel Highest
Product pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Container High
Product Manifest specification-title exo-kernel Medium
Product pom artifactid exo.kernel.container Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product pom name eXo PLF:: Kernel :: Container High
Product pom parent-groupid org.exoplatform.kernel Low
Product file name exo.kernel.container High
Version pom version 5.3.x-20190523.135107-3 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.container:5.3.x-SNAPSHOT
Confidence :High
activation-1.1.1.jar
Description: The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/activation/activation/1.1.1/activation-1.1.1.jar
MD5: 46a37512971d8eca81c3fcf245bf07d2
SHA1: 485de3a253e23f645037828c07f1d7f1af40763a
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Highest
Vendor central groupid javax.activation Highest
Vendor pom groupid javax.activation Highest
Vendor Manifest extension-name javax.activation Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid activation Low
Vendor pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor pom name JavaBeans(TM) Activation Framework High
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor file name activation High
Product pom artifactid activation Highest
Product Manifest extension-name javax.activation Medium
Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium
Product pom groupid javax.activation Low
Product pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Product pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Medium
Product pom name JavaBeans(TM) Activation Framework High
Product central artifactid activation Highest
Product file name activation High
Version central version 1.1.1 Highest
Version file version 1.1.1 Highest
Version Manifest Implementation-Version 1.1.1 High
Version pom version 1.1.1 Highest
mail-1.4.7.jar
Description: JavaMail API (compat)
License:
http://www.sun.com/cddl, https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/ciagent/.m2/repository/javax/mail/mail/1.4.7/mail-1.4.7.jar
MD5: 77f53ff0c78ba43c4812ecc9f53e20f8
SHA1: 9add058589d5d85adeb625859bf2c5eeaaedf12d
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Vendor Manifest specification-vendor Oracle Low
Vendor file name mail High
Vendor Manifest (hint) specification-vendor sun Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom parent-groupid com.sun.mail Medium
Vendor central groupid javax.mail High
Vendor pom artifactid mail Low
Vendor pom groupid javax.mail Highest
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom parent-artifactid all Low
Vendor Manifest bundle-symbolicname javax.mail Medium
Vendor pom name JavaMail API (compat) High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest extension-name javax.mail Medium
Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Vendor manifest Bundle-Description JavaMail API (compat) Medium
Vendor Manifest Implementation-Vendor Oracle High
Product Manifest bundle-docurl http://www.oracle.com Low
Product pom parent-artifactid all Medium
Product central artifactid mail-1.4.7 High
Product Manifest Implementation-Title javax.mail High
Product Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Product Manifest Bundle-Name JavaMail API (compat) Medium
Product central artifactid mail High
Product file name mail High
Product pom parent-groupid com.sun.mail Low
Product Manifest specification-title JavaMail(TM) API Design Specification Medium
Product Manifest bundle-symbolicname javax.mail Medium
Product pom artifactid mail Highest
Product pom name JavaMail API (compat) High
Product Manifest extension-name javax.mail Medium
Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Product manifest Bundle-Description JavaMail API (compat) Medium
Product pom groupid javax.mail Low
Version Manifest Implementation-Version 1.4.7 High
Version file version 1.4.7 Highest
commons-fileupload-1.3.3.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-fileupload/commons-fileupload/1.3.3/commons-fileupload-1.3.3.jar
MD5: dd77e787b7b5dc56f6a1cb658716d55d
SHA1: 04ff14d809195b711fd6bcc87e6777f886730ca1
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid commons-fileupload Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Vendor manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest
Vendor pom name Apache Commons FileUpload High
Vendor pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid commons-fileupload Highest
Vendor file name commons-fileupload High
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid commons-fileupload Highest
Vendor Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Product manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom parent-artifactid commons-parent Medium
Product Manifest specification-title Apache Commons FileUpload Medium
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-fileupload Highest
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Product pom name Apache Commons FileUpload High
Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium
Product pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom groupid commons-fileupload Low
Product pom artifactid commons-fileupload Highest
Product Manifest Implementation-Title Apache Commons FileUpload High
Product file name commons-fileupload High
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Version central version 1.3.3 Highest
Version Manifest Implementation-Version 1.3.3 High
Version file version 1.3.3 Highest
Version pom version 1.3.3 Highest
exo.ws.rest.core-5.3.x-SNAPSHOT.jar
Description: Implementation of REST Core for Exoplatform SAS 'Web Services' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.core/5.3.x-SNAPSHOT/exo.ws.rest.core-5.3.x-SNAPSHOT.jar
MD5: 44bf545ee3d289362f22532c0760547b
SHA1: 03ac20ae6703e58212d45e4e153056957e97d413
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.ws.rest.core High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.ws Medium
Vendor pom parent-artifactid ws-parent Low
Vendor pom groupid exoplatform.ws Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid exo.ws.rest.core Low
Vendor pom name eXo PLF:: WS :: REST :: Core High
Vendor pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid org.exoplatform.ws Highest
Vendor pom parent-groupid org.exoplatform.ws Medium
Product file name exo.ws.rest.core High
Product Manifest specification-title exo-ws Medium
Product Manifest Implementation-Title eXo PLF:: WS :: REST :: Core High
Product pom parent-artifactid ws-parent Medium
Product pom name eXo PLF:: WS :: REST :: Core High
Product pom artifactid exo.ws.rest.core Highest
Product pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Product pom groupid exoplatform.ws Low
Product pom parent-groupid org.exoplatform.ws Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.ws.commons-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.commons/5.3.x-SNAPSHOT/exo.ws.commons-5.3.x-SNAPSHOT.jar
SHA1: e3f538d0cc5bcf6360c9e00a0a4a4faabaf4ec6f
MD5: 916508b41039c72e9c729da2a0093689
exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.ext/5.3.x-SNAPSHOT/exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
SHA1: 88042104a09fa910f5bb1adb127d1920006a2c70
MD5: a6475d4ab27f39f470a8f262c7d59c56
maven: org.exoplatform.ws:exo.ws.rest.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:ws_project:ws:5.3
Confidence :Low
suppress
exo.ws.testframework-5.3.x-SNAPSHOT.jar
Description: Implementation of HTTP testframework for Exoplatform SAS 'Web Services' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.testframework/5.3.x-SNAPSHOT/exo.ws.testframework-5.3.x-SNAPSHOT.jar
MD5: 7591437abfe933b6061315df1014c03c
SHA1: 15d40553d17a3df0600ed3f8acb2ffff93b7c2a3
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.ws.testframework High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.ws Medium
Vendor pom parent-artifactid ws-parent Low
Vendor pom groupid exoplatform.ws Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom description Implementation of HTTP testframework for Exoplatform SAS 'Web Services' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid org.exoplatform.ws Highest
Vendor pom artifactid exo.ws.testframework Low
Vendor pom name eXo PLF:: WS :: HTTP :: testframework High
Vendor pom parent-groupid org.exoplatform.ws Medium
Product file name exo.ws.testframework High
Product pom artifactid exo.ws.testframework Highest
Product Manifest Implementation-Title eXo PLF:: WS :: HTTP :: testframework High
Product Manifest specification-title exo-ws Medium
Product pom parent-artifactid ws-parent Medium
Product pom description Implementation of HTTP testframework for Exoplatform SAS 'Web Services' project. Medium
Product pom name eXo PLF:: WS :: HTTP :: testframework High
Product pom groupid exoplatform.ws Low
Product pom parent-groupid org.exoplatform.ws Low
Version pom version 5.3.x-20190523.140828-3 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.frameworks.json/5.3.x-SNAPSHOT/exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
SHA1: df209c8abb20a199ff8f2565e38bba1377c83823
MD5: c303411215db30445ba0f14bef9d6e66
cpe: cpe:/a:ws_project:ws:5.3.20190523
Confidence :Low
suppress
maven: org.exoplatform.ws:exo.ws.testframework:5.3.x-SNAPSHOT
Confidence :High
common-logging-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-logging/2.2.2.Final/common-logging-2.2.2.Final.jar
MD5: 28b7108ee63899bca08636d360e7df11
SHA1: aee18008518671fb10982c0fe5f7383e98f71c47
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Vendor pom name GateIn - Common component (logging) High
Vendor central groupid org.gatein.common Highest
Vendor pom parent-artifactid common-parent Low
Vendor file name common-logging High
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom groupid org.gatein.common Highest
Vendor pom parent-groupid org.gatein.common Medium
Vendor pom artifactid common-logging Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid gatein.common Highest
Vendor Manifest os-name Linux Medium
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product pom groupid gatein.common Low
Product Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Product pom name GateIn - Common component (logging) High
Product pom parent-groupid org.gatein.common Low
Product file name common-logging High
Product Manifest Implementation-Title GateIn - Common component (logging) High
Product pom artifactid common-logging Highest
Product Manifest specification-title GateIn - Common component (logging) Medium
Product central artifactid common-logging Highest
Product Manifest os-name Linux Medium
Product pom parent-artifactid common-parent Medium
Version Manifest Implementation-Version 2.2.2.Final High
Version central version 2.2.2.Final Highest
Version pom version 2.2.2.Final Highest
Version file version 2.2.2 Highest
commons-dbcp-1.4.jar
Description: Commons Database Connection Pooling
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://commons.apache.org/dbcp/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Vendor pom groupid commons-dbcp Highest
Vendor file name commons-dbcp High
Vendor Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Vendor pom artifactid commons-dbcp Low
Vendor pom description Commons Database Connection Pooling Medium
Vendor central groupid commons-dbcp Highest
Vendor pom name Commons DBCP High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description Commons Database Connection Pooling Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Product Manifest Implementation-Title Commons DBCP High
Product Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Product pom parent-artifactid commons-parent Medium
Product file name commons-dbcp High
Product Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Product Manifest Bundle-Name Commons DBCP Medium
Product pom parent-groupid org.apache.commons Low
Product pom url http://commons.apache.org/dbcp/ Medium
Product pom description Commons Database Connection Pooling Medium
Product pom name Commons DBCP High
Product pom artifactid commons-dbcp Highest
Product pom groupid commons-dbcp Low
Product Manifest specification-title Commons DBCP Medium
Product central artifactid commons-dbcp Highest
Product manifest Bundle-Description Commons Database Connection Pooling Medium
Version Manifest Implementation-Version 1.4 High
Version central version 1.4 Highest
Version file version 1.4 Highest
Version pom version 1.4 Highest
jcip-annotations-1.0.jar
File Path: /home/ciagent/.m2/repository/net/jcip/jcip-annotations/1.0/jcip-annotations-1.0.jar
MD5: 9d5272954896c5a5d234f66b7372b17a
SHA1: afba4942caaeaf46aab0b976afd57cc7c181467e
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid net.jcip Highest
Vendor file name jcip-annotations High
Vendor jar package name net Low
Vendor pom artifactid jcip-annotations Low
Vendor jar package name annotations Low
Vendor pom name "Java Concurrency in Practice" book annotations High
Vendor jar package name jcip Low
Vendor pom url http://jcip.net/ Highest
Vendor central groupid net.jcip Highest
Product pom url http://jcip.net/ Medium
Product file name jcip-annotations High
Product jar package name annotations Low
Product central artifactid jcip-annotations Highest
Product pom name "Java Concurrency in Practice" book annotations High
Product jar package name jcip Low
Product pom artifactid jcip-annotations Highest
Product pom groupid net.jcip Low
Version pom version 1.0 Highest
Version file version 1.0 Highest
Version central version 1.0 Highest
exo.portal.component.test.core-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.test.core/5.3.x-SNAPSHOT/exo.portal.component.test.core-5.3.x-SNAPSHOT.jar
MD5: 47045c3ae83c77217da32f8e96bdde6a
SHA1: 5538fbd740a2d107ccac210ee887b6d9e8e4a602
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.gatein.portal Highest
Vendor file name exo.portal.component.test.core High
Vendor Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.component/exo.portal.component.test/exo.portal.component.test.core/ Low
Vendor pom parent-artifactid exo.portal.component.test Low
Vendor pom name GateIn Portal Component Core Test High
Vendor pom groupid exoplatform.gatein.portal Highest
Vendor Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid exo.portal.component.test.core Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.portal Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom parent-groupid org.exoplatform.gatein.portal Medium
Vendor Manifest os-name Linux Medium
Product Manifest specification-title GateIn Portal Component Core Test Medium
Product Manifest Implementation-Title GateIn Portal Component Core Test High
Product pom parent-groupid org.exoplatform.gatein.portal Low
Product file name exo.portal.component.test.core High
Product Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.component/exo.portal.component.test/exo.portal.component.test.core/ Low
Product pom groupid exoplatform.gatein.portal Low
Product pom parent-artifactid exo.portal.component.test Medium
Product pom name GateIn Portal Component Core Test High
Product pom artifactid exo.portal.component.test.core Highest
Product Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Product Manifest os-name Linux Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.portal.component.common-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.common/5.3.x-SNAPSHOT/exo.portal.component.common-5.3.x-SNAPSHOT.jar
SHA1: b1490240b45a4cd6c9dafd1a91e699c6fb2105f0
MD5: 2392ffd0fd1d546111f3534caad4c85d
exo.portal.component.web.security-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.security/5.3.x-SNAPSHOT/exo.portal.component.web.security-5.3.x-SNAPSHOT.jar
SHA1: e37beac9738288445a37d22bb35f7658625cac00
MD5: e5a36a0c806d6c1a5636f000d91d4a15
exo.portal.component.scripting-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.scripting/5.3.x-SNAPSHOT/exo.portal.component.scripting-5.3.x-SNAPSHOT.jar
SHA1: 06f89c090ce9b36c00cc9087ea6769a45901e19b
MD5: 12d3305d4cb34b5807cce436589455b9
exo.portal.component.resources-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.resources/5.3.x-SNAPSHOT/exo.portal.component.resources-5.3.x-SNAPSHOT.jar
SHA1: c23cb03c0f52b2dd68bcd86b8113a185ed30bd6b
MD5: 123ae03a809ba15e1ba8149c634670ca
maven: org.exoplatform.gatein.portal:exo.portal.component.test.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:in-portal:in-portal:5.3
Confidence :Low
suppress
javax.servlet-api-3.0.1.jar
Description: Java.net - The Source for Java Technology Collaboration
License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/ciagent/.m2/repository/javax/servlet/javax.servlet-api/3.0.1/javax.servlet-api-3.0.1.jar
MD5: 3ef236ac4c24850cd54abff60be25f35
SHA1: 6bf0ebb7efd993e222fc1112377b5e92a13b38dd
Referenced In Project/Scope:
eXo PLF:: ECMS Testing:provided
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.servlet Highest
Vendor pom parent-artifactid jvnet-parent Low
Vendor manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Vendor pom parent-groupid net.java Medium
Vendor Manifest specification-vendor Oracle Low
Vendor pom artifactid javax.servlet-api Low
Vendor pom organization name GlassFish Community High
Vendor Manifest (hint) specification-vendor sun Low
Vendor file name javax.servlet-api High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low
Vendor pom organization url https://glassfish.dev.java.net Medium
Vendor pom url http://servlet-spec.java.net Highest
Vendor Manifest extension-name javax.servlet Medium
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor pom name Java Servlet API High
Vendor central groupid javax.servlet Highest
Vendor Manifest bundle-symbolicname javax.servlet-api Medium
Product central artifactid javax.servlet-api Highest
Product manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Product Manifest Bundle-Name Java Servlet API Medium
Product pom organization url https://glassfish.dev.java.net Low
Product file name javax.servlet-api High
Product Manifest bundle-docurl https://glassfish.dev.java.net Low
Product pom parent-groupid net.java Low
Product Manifest extension-name javax.servlet Medium
Product pom parent-artifactid jvnet-parent Medium
Product pom url http://servlet-spec.java.net Medium
Product Manifest specification-title Java(TM) Servlet API Design Specification Medium
Product pom organization name GlassFish Community Low
Product pom name Java Servlet API High
Product Manifest bundle-symbolicname javax.servlet-api Medium
Product pom artifactid javax.servlet-api Highest
Product pom groupid javax.servlet Low
Version pom version 3.0.1 Highest
Version central version 3.0.1 Highest
Version file version 3.0.1 Highest
Version Manifest Implementation-Version 3.0.1 High
closure-compiler-v20170910.jar/META-INF/maven/com.google.javascript/closure-compiler/pom.xml
Description:
Closure Compiler is a JavaScript optimizing compiler. It parses your
JavaScript, analyzes it, removes dead code and rewrites and minimizes
what's left. It also checks syntax, variable references, and types, and
warns about common JavaScript pitfalls. It is used in many of Google's
JavaScript apps, including Gmail, Google Web Search, Google Maps, and
Google Docs.
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar/META-INF/maven/com.google.javascript/closure-compiler/pom.xml
MD5: 1b66a934999bffadab1ef6f26b68288b
SHA1: c4f1e36254f80d8b202705a678e804bc484c1e27
Evidence
Type Source Name Value Confidence
Vendor pom groupid google.javascript Highest
Vendor pom parent-groupid com.google.javascript Medium
Vendor pom parent-artifactid closure-compiler-main Low
Vendor pom artifactid closure-compiler Low
Vendor pom name Closure Compiler High
Vendor pom url https://developers.google.com/closure/compiler/ Highest
Vendor pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low
Product pom url https://developers.google.com/closure/compiler/ Medium
Product pom parent-groupid com.google.javascript Low
Product pom parent-artifactid closure-compiler-main Medium
Product pom artifactid closure-compiler Highest
Product pom name Closure Compiler High
Product pom groupid google.javascript Low
Product pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low
Version pom version v20170910 Highest
maven: com.google.javascript:closure-compiler:v20170910
Confidence :High
cpe: cpe:/a:google:gmail:-
Confidence :Low
suppress
Published Vulnerabilities
CVE-2017-17689 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-310 Cryptographic Issues
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Vulnerable Software & Versions: (show all )
closure-compiler-v20170910.jar/META-INF/maven/com.google.guava/guava/pom.xml
Description:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar/META-INF/maven/com.google.guava/guava/pom.xml
MD5: f024fd287c62f49f218990c6b57e2fdf
SHA1: 386bd381301224cac5ae8d2c7883b90a12192d79
Evidence
Type Source Name Value Confidence
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Vendor pom groupid google.guava Highest
Vendor pom parent-groupid com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom parent-artifactid guava-parent Low
Product pom name Guava: Google Core Libraries for Java High
Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Product pom parent-groupid com.google.guava Low
Product pom groupid google.guava Low
Product pom artifactid guava Highest
Product pom parent-artifactid guava-parent Medium
Version pom version 20.0 Highest
Published Vulnerabilities
CVE-2018-10237 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Vulnerable Software & Versions: (show all )
closure-compiler-v20170910.jar/META-INF/maven/com.google.protobuf/protobuf-java/pom.xml
Description:
Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an
efficient yet extensible format.
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar/META-INF/maven/com.google.protobuf/protobuf-java/pom.xml
MD5: 227a8b08fa4a124831258f4c8c774092
SHA1: 5dc19d1f724edfb259119a773d951935a1d72bfd
Evidence
Type Source Name Value Confidence
Vendor pom artifactid protobuf-java Low
Vendor pom parent-artifactid protobuf-parent Low
Vendor pom description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Vendor pom parent-groupid com.google.protobuf Medium
Vendor pom groupid google.protobuf Highest
Vendor pom name Protocol Buffers [Core] High
Product pom artifactid protobuf-java Highest
Product pom description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Product pom parent-groupid com.google.protobuf Low
Product pom parent-artifactid protobuf-parent Medium
Product pom groupid google.protobuf Low
Product pom name Protocol Buffers [Core] High
Version pom version 3.0.2 Highest
Published Vulnerabilities
CVE-2015-5237 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
Vulnerable Software & Versions: (show all )
closure-compiler-v20170910.jar/META-INF/maven/com.google.code.findbugs/jsr305/pom.xml
Description: JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar/META-INF/maven/com.google.code.findbugs/jsr305/pom.xml
MD5: d08567d16867a0b79bc8149683918452
SHA1: d04690f71f3393e23f30998d9534365274fa5f9f
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jsr305 Low
Vendor pom name FindBugs-jsr305 High
Vendor pom description JSR305 Annotations for Findbugs Medium
Vendor pom groupid google.code.findbugs Highest
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product pom name FindBugs-jsr305 High
Product pom description JSR305 Annotations for Findbugs Medium
Product pom url http://findbugs.sourceforge.net/ Medium
Product pom artifactid jsr305 Highest
Product pom groupid google.code.findbugs Low
Version pom version 3.0.1 Highest
maven: com.google.code.findbugs:jsr305:3.0.1
Confidence :High
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml
Description: JBoss Marshalling API
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml
MD5: 2b0e9541ec4a0f19e378eaabc5e85ea0
SHA1: da91abf3554dceed9454faa89acafc48c0649df5
Evidence
Type Source Name Value Confidence
Vendor pom name JBoss Marshalling API High
Vendor pom artifactid jboss-marshalling Low
Vendor pom description JBoss Marshalling API Medium
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom parent-groupid org.jboss.marshalling Low
Product pom name JBoss Marshalling API High
Product pom groupid jboss.marshalling Low
Product pom parent-artifactid jboss-marshalling-parent Medium
Product pom description JBoss Marshalling API Medium
Product pom artifactid jboss-marshalling Highest
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling:2.0.0.Beta3
Confidence :High
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml
Description: JBoss Marshalling River Implementation
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml
MD5: 1dda062cdd15bd160a4ee6cf1be9f93d
SHA1: 366411529f00ec1eb4451b9b45012bfc09bde34b
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-marshalling-river Low
Vendor pom description JBoss Marshalling River Implementation Medium
Vendor pom name JBoss Marshalling River High
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom parent-groupid org.jboss.marshalling Low
Product pom description JBoss Marshalling River Implementation Medium
Product pom artifactid jboss-marshalling-river Highest
Product pom groupid jboss.marshalling Low
Product pom name JBoss Marshalling River High
Product pom parent-artifactid jboss-marshalling-parent Medium
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling-river:2.0.0.Beta3
Confidence :High
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml
Description: JBoss Marshalling Serial Implementation
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml
MD5: 16b74097e7ec70db37b74205776ad0a7
SHA1: cf519c8805a14e6ce20933b7a89bfe0d5a7dbf0f
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-marshalling-serial Low
Vendor pom name JBoss Marshalling Serial High
Vendor pom description JBoss Marshalling Serial Implementation Medium
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom parent-groupid org.jboss.marshalling Low
Product pom artifactid jboss-marshalling-serial Highest
Product pom groupid jboss.marshalling Low
Product pom parent-artifactid jboss-marshalling-parent Medium
Product pom name JBoss Marshalling Serial High
Product pom description JBoss Marshalling Serial Implementation Medium
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling-serial:2.0.0.Beta3
Confidence :High