Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: google group | github issues

Project: eXo PLF:: Platform Public Distributions

org.exoplatform.platform.distributions:plf-public-distributions:5.2.x-SNAPSHOT

Scan Information (show all):

Display: Showing Vulnerable Dependencies (click to show all)

Dependency CPE Coordinates Highest Severity CVE Count CPE Confidence Evidence Count
tomcat-juli-8.5.35.jar cpe:/a:apache_software_foundation:tomcat:8.5.35 org.apache.tomcat:tomcat-juli:8.5.35    0 Low 21
tomcat-api-8.5.35.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-api:8.5.35  High 3 Low 21
tomcat-jni-8.5.35.jar cpe:/a:apache:tomcat_native:8.5.35
cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-jni:8.5.35  High 3 Low 21
tomcat-coyote-8.5.35.jar cpe:/a:apache:coyote_http_connector:8.5.35
cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache:tomcat_connectors:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-coyote:8.5.35  High 3 Low 21
mime-util-2.1.3.jar eu.medsea.mimeutil:mime-util:2.1.3    0 30
jakarta-regexp-1.4.jar jakarta-regexp:jakarta-regexp:1.4    0 14
xpp3-1.1.6.jar org.ogce:xpp3:1.1.6    0 24
jcl-over-slf4j-1.7.7.jar org.slf4j:jcl-over-slf4j:1.7.7    0 31
slf4j-api-1.7.7.jar org.slf4j:slf4j-api:1.7.7    0 31
exo.kernel.commons-5.2.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.commons:5.2.x-SNAPSHOT   0 24
commons-beanutils-1.8.3.jar cpe:/a:apache:commons_beanutils:1.8.3 commons-beanutils:commons-beanutils:1.8.3  High 1 Low 34
common-common-2.2.2.Final.jar org.gatein.common:common-common:2.2.2.Final    0 31
wci-wci-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.wci:wci-wci:5.2.x-SNAPSHOT   0 29
jibx-run-1.2.6.jar org.jibx:jibx-run:1.2.6    0 29
javax.inject-1.jar javax.inject:javax.inject:1    0 20
jsr250-api-1.0.jar javax.annotation:jsr250-api:1.0    0 20
cdi-api-1.0-SP4.jar javax.enterprise:cdi-api:1.0-SP4    0 31
exo.kernel.container-5.2.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.container:5.2.x-SNAPSHOT   0 24
wci-tomcat8-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.wci:wci-tomcat8:5.2.x-SNAPSHOT   0 27
calendar-webapp-5.2.x-SNAPSHOT.war org.exoplatform.calendar:calendar-webapp:5.2.x-SNAPSHOT   0 28
commons-lang-2.6.jar commons-lang:commons-lang:2.6    0 34
jcr-1.0.1.jar cpe:/a:content_project:content:1.0.1 javax.jcr:jcr:1.0.1 Medium 1 Low 25
mail-1.4.7.jar cpe:/a:sun:javamail:1.4.7 javax.mail:mail:1.4.7    0 Low 41
portlet-api-2.0.jar javax.portlet:portlet-api:2.0    0 22
commons-chain-1.2.jar commons-chain:commons-chain:1.2    0 34
commons-httpclient-3.1.jar cpe:/a:apache:httpclient:3.1
cpe:/a:apache:commons-httpclient:3.1
commons-httpclient:commons-httpclient:3.1    0 Low 24
ical4j-1.0-beta5.jar ical4j:ical4j:1.0-beta5   0 21
jackrabbit-webdav-1.6.5.jar cpe:/a:apache:jackrabbit:1.6.5 org.apache.jackrabbit:jackrabbit-webdav:1.6.5  Medium 1 Low 26
commons-digester-2.1.jar commons-digester:commons-digester:2.1    0 34
exo.kernel.component.command-5.2.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.command:5.2.x-SNAPSHOT   0 22
c3p0-0.9.1.1.jar c3p0:c3p0:0.9.1.1    0 23
quartz-2.2.2.jar org.quartz-scheduler:quartz:2.2.2    0 43
calendar-service-5.2.x-SNAPSHOT.jar org.exoplatform.calendar:calendar-service:5.2.x-SNAPSHOT   0 28
jackson-core-2.4.2.jar cpe:/a:fasterxml:jackson:2.4.2 com.fasterxml.jackson.core:jackson-core:2.4.2    0 Low 37
jackson-annotations-2.4.0.jar cpe:/a:fasterxml:jackson:2.4.0 com.fasterxml.jackson.core:jackson-annotations:2.4.0    0 Low 37
stax2-api-3.1.4.jar org.codehaus.woodstox:stax2-api:3.1.4    0 29
jackson-dataformat-xml-2.4.2.jar cpe:/a:fasterxml:jackson-databind:2.4.2
cpe:/a:fasterxml:jackson:2.4.2
com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.4.2  High 13 Highest 37
swagger-annotations-1.5.0.jar io.swagger:swagger-annotations:1.5.0    0 24
swagger-models-1.5.0.jar io.swagger:swagger-models:1.5.0    0 24
swagger-core-1.5.0.jar io.swagger:swagger-core:1.5.0    0 17
annotations-2.0.1.jar com.google.code.findbugs:annotations:2.0.1    0 23
reflections-0.9.9.jar org.reflections:reflections:0.9.9    0 19
swagger-jaxrs-1.5.0.jar io.swagger:swagger-jaxrs:1.5.0    0 17
calendar-webservice-5.2.x-SNAPSHOT.jar org.exoplatform.calendar:calendar-webservice:5.2.x-SNAPSHOT   0 28
exo.ws.commons-5.2.x-SNAPSHOT.jar cpe:/a:ws_project:ws:5.2 org.exoplatform.ws:exo.ws.commons:5.2.x-SNAPSHOT   0 Low 22
bayeux-api-3.0.8.jar org.cometd.java:bayeux-api:3.0.8    0 29
cometd-java-common-3.0.8.jar org.cometd.java:cometd-java-common:3.0.8    0 29
cometd-java-websocket-javax-server-3.0.8.jar org.cometd.java:cometd-java-websocket-javax-server:3.0.8    0 29
cometd-java-websocket-common-server-3.0.8.jar org.cometd.java:cometd-java-websocket-common-server:3.0.8    0 29
cometd-java-annotations-3.0.8.jar org.cometd.java:cometd-java-annotations:3.0.8    0 29
jetty-io-9.2.14.v20151106.jar org.eclipse.jetty:jetty-io:9.2.14.v20151106    0 35
cometd-java-client-3.0.8.jar org.cometd.java:cometd-java-client:3.0.8    0 29
cometd-java-websocket-common-client-3.0.8.jar org.cometd.java:cometd-java-websocket-common-client:3.0.8    0 29
cometd-java-websocket-javax-client-3.0.8.jar org.cometd.java:cometd-java-websocket-javax-client:3.0.8    0 29
cometd-java-oort-3.0.8.jar org.cometd.java:cometd-java-oort:3.0.8    0 29
jetty-jmx-9.2.14.v20151106.jar cpe:/a:jetty:jetty:9.2.14.v20151106
cpe:/a:eclipse:jetty:9.2.14.v20151106
org.eclipse.jetty:jetty-jmx:9.2.14.v20151106  High 4 Low 37
cometd-java-server-3.0.8.jar org.cometd.java:cometd-java-server:3.0.8    0 29
commons-comet-service-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-comet-service:5.2.x-SNAPSHOT   0 26
commons-webui-ext-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-webui-ext:5.2.x-SNAPSHOT   0 26
chromattic.core-1.3.0.jar org.chromattic:chromattic.core:1.3.0    0 23
aspectjrt-1.8.8.jar org.aspectj:aspectjrt:1.8.8    0 21
owasp-java-html-sanitizer-20160413.1.jar cpe:/a:owasp-java-html-sanitizer_project:owasp-java-html-sanitizer:20160413.1 com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer:20160413.1    0 Low 21
jrcs.diff-0.4.2.jar org.jvnet.hudson:org.suigeneris.jrcs.diff:0.4.2    0 17
ecs-1.4.2.jar ecs:ecs:1.4.2    0 14
liquibase-core-3.4.2.jar org.liquibase:liquibase-core:3.4.2    0 19
dom4j-1.6.1.jar cpe:/a:dom4j_project:dom4j:1.6.1 dom4j:dom4j:1.6.1  Medium 1 Highest 31
javassist-3.20.0-GA.jar org.javassist:javassist:3.20.0-GA    0 27
hibernate-jpa-2.0-api-1.0.1.Final.jar org.hibernate.javax.persistence:hibernate-jpa-2.0-api:1.0.1.Final    0 26
hibernate-entitymanager-4.2.21.Final.jar org.hibernate:hibernate-entitymanager:4.2.21.Final    0 32
commons-component-common-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-component-common:5.2.x-SNAPSHOT   0 26
antlr-2.7.7.jar antlr:antlr:2.7.7    0 18
hibernate-core-4.2.21.Final.jar org.hibernate:hibernate-core:4.2.21.Final    0 32
exo.core.component.organization.api-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.organization.api:5.2.x-SNAPSHOT   0 22
exo.core.component.security.core-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.security.core:5.2.x-SNAPSHOT   0 24
lucene-core-3.6.2.jar org.apache.lucene:lucene-core:3.6.2    0 26
lucene-analyzers-3.6.2.jar org.apache.lucene:lucene-analyzers:3.6.2    0 26
lucene-spellchecker-3.6.2.jar org.apache.lucene:lucene-spellchecker:3.6.2    0 26
jta-1.1.jar javax.transaction:transaction-api:1.1    0 22
concurrent-1.3.4.jar concurrent:concurrent:1.3.4    0 23
commons-collections-3.2.2.jar cpe:/a:apache:commons_collections:3.2.2 commons-collections:commons-collections:3.2.2    0 Low 40
jgroups-3.6.13.Final.jar org.jgroups:jgroups:3.6.13.Final    0 32
jbossjta-4.16.6.Final.jar org.jboss.jbossts:jbossjta:4.16.6.Final    0 22
ws-commons-util-1.0.1.jar cpe:/a:ws_project:ws:1.0.1 ws-commons-util:ws-commons-util:1.0.1  Medium 1 Low 30
jboss-common-core-2.2.22.GA.jar org.jboss:jboss-common-core:2.2.22.GA    0 30
stringtemplate-3.2.1.jar org.antlr:stringtemplate:3.2.1    0 23
antlr-runtime-3.5.jar org.antlr:antlr-runtime:3.5    0 26
exo.kernel.component.ext.cache.impl.infinispan.v8-5.2.x-SNAPSHOT.jar cpe:/a:infinispan:infinispan:5.2.0 org.exoplatform.kernel:exo.kernel.component.ext.cache.impl.infinispan.v8:5.2.x-SNAPSHOT Medium 3 Highest 24
jboss-marshalling-osgi-2.0.0.Beta3.jar org.jboss.marshalling:jboss-marshalling-osgi:2.0.0.Beta3    0 29
infinispan-core-8.2.6.Final.jar cpe:/a:infinispan:infinispan:8.2.6 org.infinispan:infinispan-core:8.2.6.Final  Medium 3 Highest 35
exo.jcr.component.core-5.2.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.component.core:5.2.x-SNAPSHOT   0 24
commons-dbcp-1.4.jar commons-dbcp:commons-dbcp:1.4    0 34
commons-pool-1.6.jar commons-pool:commons-pool:1.6    0 36
exo.kernel.component.common-5.2.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.common:5.2.x-SNAPSHOT   0 24
exo.portal.webui.core-5.2.x-SNAPSHOT.jar cpe:/a:in-portal:in-portal:5.2.0 org.exoplatform.gatein.portal:exo.portal.webui.core:5.2.x-SNAPSHOT Medium 1 Highest 29
icu4j-56.1.jar cpe:/a:icu-project:international_components_for_unicode:56.1::~~~c%2fc%2b%2b~~ com.ibm.icu:icu4j:56.1  High 8 Highest 33
common-logging-2.2.2.Final.jar org.gatein.common:common-logging:2.2.2.Final    0 31
social-component-core-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-core:5.2.x-SNAPSHOT   0 28
social-component-common-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-common:5.2.x-SNAPSHOT   0 28
staxnav.core-0.9.8.jar org.staxnav:staxnav.core:0.9.8    0 19
commons-lang3-3.3.2.jar org.apache.commons:commons-lang3:3.3.2    0 37
pc-federation-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-federation:5.2.x-SNAPSHOT   0 29
pc-bridge-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-bridge:5.2.x-SNAPSHOT   0 29
picketlink-idm-core-1.4.6.Final.jar cpe:/a:picketlink:picketlink:1.4.6 org.picketlink.idm:picketlink-idm-core:1.4.6.Final  Medium 3 Low 37
mop-api-1.3.2.Final.jar org.gatein.mop:mop-api:1.3.2.Final   0 30
mop-spi-1.3.2.Final.jar org.gatein.mop:mop-spi:1.3.2.Final   0 30
mop-core-1.3.2.Final.jar org.gatein.mop:mop-core:1.3.2.Final   0 30
gatein-management-spi-2.1.0.Final.jar org.gatein.management:gatein-management-spi:2.1.0.Final   0 28
args4j-2.0.16.jar args4j:args4j:2.0.16    0 20
closure-compiler-v20131014.jar cpe:/a:google:gmail:- com.google.javascript:closure-compiler:v20131014  Medium 1 Low 28
filters-2.0.235.jar cpe:/a:image_processing_software:image_processing_software:2.0.235 com.jhlabs:filters:2.0.235  Low 1 Low 22
simplecaptcha-1.1.1.Final-gatein-4.jar org.gatein.captcha:simplecaptcha:1.1.1.Final-gatein-4   0 27
gatein-api-1.0.1.Final.jar org.gatein.api:gatein-api:1.0.1.Final    0 29
rome-1.0.jar rome:rome:1.0    0 32
calendar-common-5.2.x-SNAPSHOT.jar org.exoplatform.calendar:calendar-common:5.2.x-SNAPSHOT   0 26
commons-comet-webapp-5.2.x-SNAPSHOT.war org.exoplatform.commons:commons-comet-webapp:5.2.x-SNAPSHOT   0 26
commons-extension-webapp-5.2.x-SNAPSHOT.war org.exoplatform.commons:commons-extension-webapp:5.2.x-SNAPSHOT   0 26
jtidy-r938.jar cpe:/a:html-tidy:tidy:- net.sf.jtidy:jtidy:r938    0 Low 25
exo.core.component.xml-processing-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.xml-processing:5.2.x-SNAPSHOT   0 24
exo.jcr.component.ext-5.2.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.component.ext:5.2.x-SNAPSHOT   0 22
ecms-apps-portlet-administration-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-apps-portlet-administration:5.2.x-SNAPSHOT   0 28
ecms-core-webui-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-webui:5.2.x-SNAPSHOT   0 28
ecms-apps-portlet-presentation-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-apps-portlet-presentation:5.2.x-SNAPSHOT   0 26
exo.jcr.component.webdav-5.2.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.component.webdav:5.2.x-SNAPSHOT   0 22
ecms-core-publication-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-publication:5.2.x-SNAPSHOT   0 28
ecms-core-search-5.2.x-SNAPSHOT.jar cpe:/a:pro_search:pro_search:5.2 org.exoplatform.ecms:ecms-core-search:5.2.x-SNAPSHOT   0 Low 24
itunes-com-podcast-0.2.jar cpe:/a:apple:itunes:0.2 com.totsp.feedpod:itunes-com-podcast:0.2  High 519 Low 29
jurt-3.2.1.jar cpe:/a:openoffice:openoffice.org:3.2.1
cpe:/a:openoffice:openoffice:3.2.1
org.openoffice:jurt:3.2.1  High 8 Highest 18
juh-3.2.1.jar cpe:/a:openoffice:openoffice.org:3.2.1
cpe:/a:openoffice:openoffice:3.2.1
org.openoffice:juh:3.2.1  High 8 Highest 20
ridl-3.2.1.jar cpe:/a:openoffice:openoffice.org:3.2.1
cpe:/a:openoffice:openoffice:3.2.1
org.openoffice:ridl:3.2.1  High 8 Highest 18
unoil-3.2.1.jar cpe:/a:openoffice:openoffice.org:3.2.1
cpe:/a:openoffice:openoffice:3.2.1
org.openoffice:unoil:3.2.1  High 8 Highest 18
jodconverter-core-3.0-eXo03.jar org.artofsolving.jodconverter:jodconverter-core:3.0-eXo03   0 21
groovy-all-2.4.12.jar cpe:/a:apache:groovy:2.4.12 org.codehaus.groovy:groovy-all:2.4.12    0 Low 36
jai-core-1.1.3.jar javax.media:jai-core:1.1.3   0 21
jai-codec-1.1.3.jar com.sun.media:jai-codec:1.1.3   0 22
icepdf-core-5.1.1.jar org.icepdf.os:icepdf-core:5.1.1   0 17
imgscalr-lib-4.2.jar org.imgscalr:imgscalr-lib:4.2    0 23
jdom-1.1.3.jar org.jdom:jdom:1.1.3    0 44
ecms-core-services-5.2.x-SNAPSHOT.jar cpe:/a:no-cms_project:no-cms:5.2.20190113 org.exoplatform.ecms:ecms-core-services:5.2.x-SNAPSHOT   0 Low 28
ecms-core-webui-presentation-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-webui-presentation:5.2.x-SNAPSHOT   0 26
ecms-ext-authoring-services-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-ext-authoring-services:5.2.x-SNAPSHOT   0 26
json-20070829.jar org.json:json:20070829    0 23
ecms-apps-portlet-seo-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-apps-portlet-seo:5.2.x-SNAPSHOT   0 24
ecms-apps-resources-wcm-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-apps-resources-wcm:5.2.x-SNAPSHOT   0 26
ecms-core-webapp-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-core-webapp:5.2.x-SNAPSHOT   0 28
commons-component-upgrade-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-component-upgrade:5.2.x-SNAPSHOT   0 26
json-simple-1.1.1.jar com.googlecode.json-simple:json-simple:1.1.1    0 23
commons-io-2.4.jar commons-io:commons-io:2.4    0 36
ecms-core-connector-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-connector:5.2.x-SNAPSHOT   0 28
ecms-core-webui-explorer-5.2.x-SNAPSHOT.jar cpe:/a:content_project:content:5.2.20190113 org.exoplatform.ecms:ecms-core-webui-explorer:5.2.x-SNAPSHOT   0 Low 28
exo.kernel.component.cache-5.2.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.cache:5.2.x-SNAPSHOT   0 22
ecms-ext-authoring-apps-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-ext-authoring-apps:5.2.x-SNAPSHOT   0 26
ecms-core-webui-fcc-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-webui-fcc:5.2.x-SNAPSHOT   0 28
ecms-packaging-wcm-webapp-5.2.x-SNAPSHOT.war org.exoplatform.ecms:ecms-packaging-wcm-webapp:5.2.x-SNAPSHOT   0 28
exo-jcr-services-5.2.x-SNAPSHOT.jar org.exoplatform:exo-jcr-services:5.2.x-SNAPSHOT   0 24
fontbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:fontbox:1.8.14  Medium 1 Highest 37
jempbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:jempbox:1.8.14  Medium 1 Highest 35
pdfbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:pdfbox:1.8.14  Medium 1 Highest 35
htmllexer-2.1.jar org.htmlparser:htmllexer:2.1    0 23
htmlparser-2.1.jar org.htmlparser:htmlparser:2.1    0 23
poi-3.13.jar cpe:/a:apache:poi:3.13 org.apache.poi:poi:3.13  High 2 Highest 28
tika-core-1.5.jar cpe:/a:apache:tika:1.5 org.apache.tika:tika-core:1.5  High 8 Highest 33
vorbis-java-core-0.1-tests.jar org.gagravarr:vorbis-java-core:0.1    0 23
vorbis-java-tika-0.1.jar cpe:/a:apache:tika:0.1 org.gagravarr:vorbis-java-tika:0.1  High 6 Highest 23
netcdf-4.2-min.jar edu.ucar:netcdf:4.2-min    0 21
apache-mime4j-core-0.7.2.jar cpe:/a:apache:james:0.7.2 org.apache.james:apache-mime4j-core:0.7.2    0 Low 33
xz-1.2.jar cpe:/a:tukaani:xz:1.2 org.tukaani:xz:1.2  Medium 1 Low 27
commons-compress-1.5.jar cpe:/a:apache:commons-compress:1.5 org.apache.commons:commons-compress:1.5    0 Low 39
tagsoup-1.2.1.jar org.ccil.cowan.tagsoup:tagsoup:1.2.1    0 18
asm-debug-all-4.1.jar org.ow2.asm:asm-debug-all:4.1    0 28
isoparser-1.0-RC-1.jar cpe:/a:boxes_project:boxes:7.x-1.0 com.googlecode.mp4parser:isoparser:1.0-RC-1  Low 1 Highest 24
xmpcore-5.1.2.jar com.adobe.xmp:xmpcore:5.1.2    0 30
metadata-extractor-2.6.2.jar com.drewnoakes:metadata-extractor:2.6.2    0 21
vorbis-java-core-0.1.jar org.gagravarr:vorbis-java-core:0.1    0 21
juniversalchardet-1.0.3.jar org.zenframework.z8.dependencies.commons:juniversalchardet-1.0.3:2.0    0 27
jhighlight-1.0.jar com.uwyn:jhighlight:1.0    0 25
xmlbeans-2.6.0.jar org.apache.xmlbeans:xmlbeans:2.6.0    0 24
exo.core.component.document-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.document:5.2.x-SNAPSHOT   0 24
ecms-core-publication-plugins-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-publication-plugins:5.2.x-SNAPSHOT   0 28
ecms-core-viewer-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-viewer:5.2.x-SNAPSHOT   0 28
ecms-core-webui-administration-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-core-webui-administration:5.2.x-SNAPSHOT   0 28
ecms-ext-authoring-webui-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-ext-authoring-webui:5.2.x-SNAPSHOT   0 26
ecms-ext-webui-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-ext-webui:5.2.x-SNAPSHOT   0 28
ecms-upgrade-plugins-5.2.x-SNAPSHOT.jar org.exoplatform.ecms:ecms-upgrade-plugins:5.2.x-SNAPSHOT   0 26
forum-forum-webapp-5.2.x-SNAPSHOT.war org.exoplatform.forum:forum-forum-webapp:5.2.x-SNAPSHOT   0 24
commons-webui-component-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-webui-component:5.2.x-SNAPSHOT   0 26
forum-application-common-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-application-common:5.2.x-SNAPSHOT   0 26
htmlcleaner-2.7.jar cpe:/a:htmlcleaner_project:htmlcleaner:2.7 net.sourceforge.htmlcleaner:htmlcleaner:2.7    0 Low 20
stax-utils-20070216.jar net.java.dev.stax-utils:stax-utils:20070216    0 20
xwiki-commons-xml-5.4.7.jar cpe:/a:xwiki:xwiki:5.4.7 org.xwiki.commons:xwiki-commons-xml:5.4.7 Low 1 Low 26
wiki-renderer-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-renderer:5.2.x-SNAPSHOT   0 26
forum-component-bbcode-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-component-bbcode:5.2.x-SNAPSHOT   0 26
forum-component-common-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-component-common:5.2.x-SNAPSHOT   0 26
forum-component-rendering-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-component-rendering:5.2.x-SNAPSHOT   0 26
forum-forum-service-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-forum-service:5.2.x-SNAPSHOT   0 26
xpp3-1.1.4c.jar xpp3:xpp3:1.1.4c    0 26
integ-search-portlet-5.2.x-SNAPSHOT.war org.exoplatform.integration:integ-search-portlet:5.2.x-SNAPSHOT   0 24
juzu-core-1.2.x-SNAPSHOT.jar org.juzu:juzu-core:1.2.x-SNAPSHOT   0 21
rhino-1.7R3.jar org.mozilla:rhino:1.7R3    0 26
juzu-plugins-less-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-less:1.2.x-SNAPSHOT   0 24
juzu-plugins-portlet-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-portlet:1.2.x-SNAPSHOT   0 24
commons-api-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-api:5.2.x-SNAPSHOT   0 26
integ-search-service-5.2.x-SNAPSHOT.jar cpe:/a:pro_search:pro_search:5.2.20190116 org.exoplatform.integration:integ-search-service:5.2.x-SNAPSHOT   0 Low 26
exo.jcr.framework.command-5.2.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.framework.command:5.2.x-SNAPSHOT   0 24
exo.jcr.framework.web-5.2.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.framework.web:5.2.x-SNAPSHOT   0 22
commons-component-product-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-component-product:5.2.x-SNAPSHOT   0 28
platform-component-upgrade-plugins-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-upgrade-plugins:5.2.x-SNAPSHOT   0 26
platform-exo-gadget-pack-gadget-pack-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-exo-gadget-pack-gadget-pack:5.2.x-SNAPSHOT   0 28
exo.core.component.script.groovy-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.script.groovy:5.2.x-SNAPSHOT   0 22
platform-exo-gadget-pack-gadget-pack-services-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-exo-gadget-pack-gadget-pack-services:5.2.x-SNAPSHOT   0 26
platform-extension-portlet-branding-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-portlet-branding:5.2.x-SNAPSHOT   0 22
commons-fileupload-1.3.3.jar cpe:/a:apache:commons_fileupload:1.3.3 commons-fileupload:commons-fileupload:1.3.3    0 Low 40
commons-juzu-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-juzu:5.2.x-SNAPSHOT   0 28
juzu-plugins-upload-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-upload:1.2.x-SNAPSHOT   0 23
platform-extension-portlets-homepage-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-portlets-homepage:5.2.x-SNAPSHOT   0 23
aopalliance-1.0.jar aopalliance:aopalliance:1.0    0 20
guice-3.0.jar com.google.inject:guice:3.0    0 29
guice-multibindings-3.0.jar com.google.inject.extensions:guice-multibindings:3.0    0 29
commons-codec-1.10.jar commons-codec:commons-codec:1.10    0 38
guava-18.0.jar cpe:/a:google:guava:18.0 com.google.guava:guava:18.0  Medium 1 Highest 27
oauth-provider-20100527.jar net.oauth.core:oauth-provider:20100527    0 18
oauth-consumer-20090617.jar net.oauth.core:oauth-consumer:20090617   0 17
oauth-httpclient4-20090913.jar net.oauth.core:oauth-httpclient4:20090913   0 20
httpcore-4.3.3.jar org.apache.httpcomponents:httpcore:4.3.3    0 32
httpclient-4.3.6.jar cpe:/a:apache:httpclient:4.3.6 org.apache.httpcomponents:httpclient:4.3.6    0 Low 32
platform-extension-portlets-platformNavigation-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-portlets-platformNavigation:5.2.x-SNAPSHOT   0 26
calendar-component-create-5.2.x-SNAPSHOT.jar org.exoplatform.calendar:calendar-component-create:5.2.x-SNAPSHOT   0 26
ecms-core-webui-seo-5.2.x-SNAPSHOT.jar cpe:/a:content_project:content:5.2 org.exoplatform.ecms:ecms-core-webui-seo:5.2.x-SNAPSHOT   0 Low 26
forum-application-create-5.2.x-SNAPSHOT.jar org.exoplatform.forum:forum-application-create:5.2.x-SNAPSHOT   0 24
platform-component-common-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-common:5.2.x-SNAPSHOT   0 26
platform-component-uxpnavigation-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-uxpnavigation:5.2.x-SNAPSHOT   0 24
platform-component-webui-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-webui:5.2.x-SNAPSHOT   0 26
social-component-webui-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-webui:5.2.x-SNAPSHOT   0 28
chromattic.common-1.3.0.jar org.chromattic:chromattic.common:1.3.0    0 25
chromattic.metamodel-1.3.0.jar org.chromattic:chromattic.metamodel:1.3.0    0 23
jboss-logging-annotations-1.2.0.Beta1.jar org.jboss.logging:jboss-logging-annotations:1.2.0.Beta1    0 30
hibernate-commons-annotations-4.0.5.Final.jar org.hibernate.common:hibernate-commons-annotations:4.0.5.Final    0 30
jackson-databind-2.3.1.jar cpe:/a:fasterxml:jackson:2.3.1
cpe:/a:fasterxml:jackson-databind:2.3.1
com.fasterxml.jackson.core:jackson-databind:2.3.1  High 13 Highest 37
social-component-service-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-service:5.2.x-SNAPSHOT   0 28
itext-2.1.7.jar com.lowagie:itext:2.1.7    0 23
validation-api-1.1.0.Final.jar javax.validation:validation-api:1.1.0.Final    0 22
sac-1.3.jar org.w3c.css:sac:1.3    0 27
cssparser-0.9.18.jar net.sourceforge.cssparser:cssparser:0.9.18    0 27
bcmail-jdk15-1.45.jar cpe:/a:no-cms_project:no-cms:1.45 org.bouncycastle:bcmail-jdk15:1.45    0 Low 24
bcprov-jdk15-1.45.jar cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45
cpe:/a:bouncycastle:bouncy_castle_crypto_package:1.45
org.bouncycastle:bcprov-jdk15:1.45  Medium 1 Low 24
bctsp-jdk15-1.45.jar org.bouncycastle:bctsp-jdk15:1.45    0 24
mchange-commons-java-0.2.3.4.jar com.mchange:mchange-commons-java:0.2.3.4    0 19
c3p0-0.9.2.1.jar com.mchange:c3p0:0.9.2.1    0 24
hibernate-c3p0-4.2.21.Final.jar org.hibernate:hibernate-c3p0:4.2.21.Final    0 32
exo.core.component.organization.jdbc-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.organization.jdbc:5.2.x-SNAPSHOT   0 22
jrcs.rcs-0.4.2.jar org.jvnet.hudson:org.suigeneris.jrcs.rcs:0.4.2    0 17
flying-saucer-core-9.0.8.jar org.xhtmlrenderer:flying-saucer-core:9.0.8    0 21
flying-saucer-pdf-9.0.8.jar org.xhtmlrenderer:flying-saucer-pdf:9.0.8    0 23
wiki-service-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-service:5.2.x-SNAPSHOT   0 26
wiki-macros-iframe-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-macros-iframe:5.2.x-SNAPSHOT   0 26
jython-standalone-2.5.4-rc1.jar cpe:/a:jython_project:jython:2.5.4.rc1 org.python:jython-standalone:2.5.4-rc1    0 Low 10
pygments-1.6.jar cpe:/a:pygments:pygments:1.6 org.pygments:pygments:1.6  High 1 Highest 18
jdom2-2.0.5.jar org.jdom:jdom2:2.0.5    0 43
wiki-webui-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-webui:5.2.x-SNAPSHOT   0 26
platform-extension-portlets-notification-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-portlets-notification:5.2.x-SNAPSHOT   0 22
platform-extension-resources-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-resources:5.2.x-SNAPSHOT   0 26
platform-extension-webapp-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-extension-webapp:5.2.x-SNAPSHOT   0 26
juzu-plugins-validation-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-validation:1.2.x-SNAPSHOT   0 24
protobuf-java-2.5.0.jar cpe:/a:google:protobuf:2.5.0 com.google.protobuf:protobuf-java:2.5.0  Medium 1 Highest 29
less4j-1.4.0.jar com.github.sommeri:less4j:1.4.0    0 24
juzu-plugins-less4j-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-less4j:1.2.x-SNAPSHOT   0 25
webjars-locator-0.4.jar org.webjars:webjars-locator:0.4    0 19
juzu-plugins-webjars-1.2.x-SNAPSHOT.jar org.juzu:juzu-plugins-webjars:1.2.x-SNAPSHOT   0 24
jsr311-api-1.1.1.jar javax.ws.rs:jsr311-api:1.1.1    0 28
chromattic.api-1.3.0.jar org.chromattic:chromattic.api:1.3.0    0 23
reflext.api-1.1.0.jar org.reflext:reflext.api:1.1.0    0 23
reflext.core-1.1.0.jar org.reflext:reflext.core:1.1.0    0 23
reflext.spi-1.1.0.jar org.reflext:reflext.spi:1.1.0    0 25
reflext.apt-1.1.0.jar org.reflext:reflext.apt:1.1.0    0 23
chromattic.apt-1.3.0.jar org.chromattic:chromattic.apt:1.3.0    0 23
chromattic.ext-1.3.0.jar org.chromattic:chromattic.ext:1.3.0    0 25
chromattic.spi-1.3.0.jar org.chromattic:chromattic.spi:1.3.0    0 25
pc-api-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-api:5.2.x-SNAPSHOT   0 27
picocontainer-1.1.jar picocontainer:picocontainer:1.1    0 28
sso-integration-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.sso:sso-integration:5.2.x-SNAPSHOT   0 31
sso-agent-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.sso:sso-agent:5.2.x-SNAPSHOT   0 29
xmlpull-1.1.3.1.jar xmlpull:xmlpull:1.1.3.1    0 18
xstream-1.4.10.jar cpe:/a:xstream_project:xstream:1.4.10 com.thoughtworks.xstream:xstream:1.4.10    0 Low 53
ccpp-1.0.jar javax.ccpp:ccpp:1.0    0 20
portals-bridges-common-1.0.4.jar org.apache.portals.bridges:portals-bridges-common:1.0.4    0 25
asm-3.1.jar asm:asm:3.1    0 18
cglib-2.2.jar cglib:cglib:2.2    0 20
chromattic.cglib-1.3.0.jar org.chromattic:chromattic.cglib:1.3.0    0 23
javaparser-1.0.8.jar com.google.code.javaparser:javaparser:1.0.8   0 20
chromattic.groovy-1.3.0.jar org.chromattic:chromattic.groovy:1.3.0    0 23
reflext.jlr-1.1.0.jar org.reflext:reflext.jlr:1.1.0    0 23
chromattic.dataobject-1.3.0.jar org.chromattic:chromattic.dataobject:1.3.0    0 23
commons-search-5.2.x-SNAPSHOT.jar cpe:/a:pro_search:pro_search:5.2.20190113 org.exoplatform.commons:commons-search:5.2.x-SNAPSHOT   0 Low 26
commons-file-storage-5.2.x-SNAPSHOT.jar org.exoplatform.commons:commons-file-storage:5.2.x-SNAPSHOT   0 26
jboss-logging-3.3.0.Final.jar org.jboss.logging:jboss-logging:3.3.0.Final    0 44
exo.core.component.database-5.2.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.database:5.2.x-SNAPSHOT   0 24
integ-calendar-social-5.2.x-SNAPSHOT.jar org.exoplatform.integration:integ-calendar-social:5.2.x-SNAPSHOT   0 28
integ-ecms-social-5.2.x-SNAPSHOT.jar org.exoplatform.integration:integ-ecms-social:5.2.x-SNAPSHOT   0 28
integ-forum-social-5.2.x-SNAPSHOT.jar org.exoplatform.integration:integ-forum-social:5.2.x-SNAPSHOT   0 26
integ-social-ecms-5.2.x-SNAPSHOT.jar org.exoplatform.integration:integ-social-ecms:5.2.x-SNAPSHOT   0 26
integ-wiki-social-5.2.x-SNAPSHOT.jar org.exoplatform.integration:integ-wiki-social:5.2.x-SNAPSHOT   0 26
platform-component-gadgets-5.2.x-SNAPSHOT.jar cpe:/a:user_dashboard_project:user_dashboard:5.2 org.exoplatform.platform:platform-component-gadgets:5.2.x-SNAPSHOT   0 Low 26
platform-component-organization-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-organization:5.2.x-SNAPSHOT   0 26
platform-extension-config-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-extension-config:5.2.x-SNAPSHOT   0 24
exo.ws.rest.core-5.2.x-SNAPSHOT.jar cpe:/a:ws_project:ws:5.2.20190113 org.exoplatform.ws:exo.ws.rest.core:5.2.x-SNAPSHOT   0 Low 24
redirect-5.2.x-SNAPSHOT.jar cpe:/a:in-portal:in-portal:5.2.0 org.gatein.web:redirect:5.2.x-SNAPSHOT Medium 1 Highest 29
hibernate-validator-4.2.0.Final.jar cpe:/a:hibernate:hibernate_validator:4.2.0 org.hibernate:hibernate-validator:4.2.0.Final  Medium 1 Highest 27
platform-sample-acme-intranet-portlet-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-sample-acme-intranet-portlet:5.2.x-SNAPSHOT   0 26
platform-sample-acme-intranet-webapp-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-sample-acme-intranet-webapp:5.2.x-SNAPSHOT   0 26
platform-sample-gadgets-sample-exo-gadget-resources-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-sample-gadgets-sample-exo-gadget-resources:5.2.x-SNAPSHOT   0 28
platform-sample-gadgets-sample-gadgets-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-sample-gadgets-sample-gadgets:5.2.x-SNAPSHOT   0 26
platform-sample-gadgets-sample-service-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-sample-gadgets-sample-service:5.2.x-SNAPSHOT   0 26
platform-registration-5.2.x-SNAPSHOT.war org.exoplatform.platform:platform-registration:5.2.x-SNAPSHOT   0 24
platform-ui-skin-5.2.x-SNAPSHOT.war org.exoplatform.platform-ui:platform-ui-skin:5.2.x-SNAPSHOT   0 26
plf-root-webapp-5.2.x-SNAPSHOT.war org.exoplatform.platform.distributions:plf-root-webapp:5.2.x-SNAPSHOT   0 26
social-extension-war-5.2.x-SNAPSHOT.war org.exoplatform.social:social-extension-war:5.2.x-SNAPSHOT   0 28
social-notification-extension-5.2.x-SNAPSHOT.war org.exoplatform.social:social-notification-extension:5.2.x-SNAPSHOT   0 28
social-component-notification-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-notification:5.2.x-SNAPSHOT   0 28
social-component-core-jpa-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-core-jpa:5.2.x-SNAPSHOT   0 26
social-extras-feedmash-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-extras-feedmash:5.2.x-SNAPSHOT   0 28
oauth-20100527.jar net.oauth.core:oauth:20100527    0 18
social-component-opensocial-5.2.x-SNAPSHOT.jar org.exoplatform.social:social-component-opensocial:5.2.x-SNAPSHOT   0 28
joda-time-2.4.jar joda-time:joda-time:2.4    0 34
ehcache-core-2.6.9.jar net.sf.ehcache:ehcache-core:2.6.9    0 19
juel-impl-2.2.7.jar de.odysseus.juel:juel-impl:2.2.7    0 26
shindig-common-2.5.2.jar cpe:/a:apache:shindig:2.5.2 org.apache.shindig:shindig-common:2.5.2    0 Low 26
caja-r5054.jar com.google.caja:caja:r5054   0 23
htmlparser-r4209.jar caja:htmlparser:r4209   0 24
nekohtml-1.9.22.jar net.sourceforge.nekohtml:nekohtml:1.9.22    0 20
xercesImpl-2.9.1.jar cpe:/a:apache:xerces2_java:2.9.1 xerces:xercesImpl:2.9.1  High 1 Low 50
sanselan-0.97-incubator.jar org.apache.sanselan:sanselan:0.97-incubator    0 35
social-webapp-portlet-5.2.x-SNAPSHOT.war cpe:/a:app_project:app:5.2 org.exoplatform.social:social-webapp-portlet:5.2.x-SNAPSHOT Medium 1 Low 26
social-webapp-juzu-portlet-5.2.x-SNAPSHOT.war org.exoplatform.social:social-webapp-juzu-portlet:5.2.x-SNAPSHOT   0 23
wiki-upgrade-plugins-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-upgrade-plugins:5.2.x-SNAPSHOT   0 28
wiki-webapp-5.2.x-SNAPSHOT.war org.exoplatform.wiki:wiki-webapp:5.2.x-SNAPSHOT   0 26
gwt-servlet-2.6.1.jar cpe:/a:google:protobuf:2.5.0
cpe:/a:google:protobuf:2.6.1
com.google.gwt:gwt-servlet:2.6.1  Medium 1 Highest 29
smartgwt-lgpl-6.0-p20170514.jar cpe:/a:widgets_project:widgets:6.0.p20170514 com.isomorphic.smartgwt.lgpl:smartgwt-lgpl:6.0-p20170514 Medium 1 Low 14
jcommon-1.0.17.jar org.jfree:jcommon:1.0.17    0 23
jfreechart-1.0.14.jar org.jfree:jfreechart:1.0.14    0 25
velocity-1.7.jar org.apache.velocity:velocity:1.7    0 33
velocity-tools-1.4.jar cpe:/a:apache:struts:1.4 velocity-tools:velocity-tools:1.4    0 Low 19
ezmorph-1.0.6.jar net.sf.ezmorph:ezmorph:1.0.6    0 22
json-lib-2.4-jdk15.jar com.hynnet:json-lib:2.4    0 15
commons-configuration-1.10.jar commons-configuration:commons-configuration:1.10    0 36
snuggletex-core-1.1.0.jar uk.ac.ed.ph.snuggletex:snuggletex-core:1.1.0   0 18
batik-css-1.7.jar cpe:/a:apache:batik:1.7 org.apache.xmlgraphics:batik-css:1.7  High 3 Highest 22
xmlgraphics-commons-1.3.1.jar org.apache.xmlgraphics:xmlgraphics-commons:1.3.1    0 25
jeuclid-core-3.1.5.jar net.sourceforge.jeuclid:jeuclid-core:3.1.5    0 22
snuggletex-jeuclid-1.1.0.jar uk.ac.ed.ph.snuggletex:snuggletex-jeuclid:1.1.0   0 18
serializer-2.7.1.jar cpe:/a:apache:xalan-java:2.7.1 xalan:serializer:2.7.1  High 1 Highest 26
xalan-2.7.1.jar cpe:/a:apache:xalan-java:2.7.1 xalan:xalan:2.7.1  High 1 Highest 40
wiki-jpa-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-jpa:5.2.x-SNAPSHOT   0 24
wiki-jpa-migration-5.2.x-SNAPSHOT.jar org.exoplatform.wiki:wiki-jpa-migration:5.2.x-SNAPSHOT   0 26
gatein-management-api-2.1.0.Final.jar org.gatein.management:gatein-management-api:2.1.0.Final   0 28
jboss-dmr-1.1.1.Final.jar org.jboss:jboss-dmr:1.1.1.Final    0 26
gatein-management-core-2.1.0.Final.jar org.gatein.management:gatein-management-core:2.1.0.Final   0 28
gatein-management-rest-2.1.0.Final.jar org.gatein.management:gatein-management-rest:2.1.0.Final   0 28
twitter4j-core-3.0.5.jar cpe:/a:twitter_project:twitter:3.0.5
cpe:/a:twitter:twitter:3.0.5
org.twitter4j:twitter4j-core:3.0.5    0 Low 22
scribe-1.3.5.jar cpe:/a:scribe:scribe:1.3.5 org.scribe:scribe:1.3.5    0 Low 23
google-http-client-1.14.1-beta.jar com.google.http-client:google-http-client:1.14.1-beta    0 24
jsr305-1.3.9.jar com.google.code.findbugs:jsr305:1.3.9    0 21
google-oauth-client-1.14.1-beta.jar com.google.oauth-client:google-oauth-client:1.14.1-beta    0 24
google-api-client-1.14.1-beta.jar com.google.api-client:google-api-client:1.14.1-beta    0 22
jackson-core-asl-1.9.11.jar cpe:/a:fasterxml:jackson:1.9.11 org.codehaus.jackson:jackson-core-asl:1.9.11    0 Low 32
google-http-client-jackson-1.14.1-beta.jar com.google.http-client:google-http-client-jackson:1.14.1-beta    0 22
google-api-services-plus-v1-rev69-1.14.2-beta.jar com.google.apis:google-api-services-plus:v1-rev69-1.14.2-beta    0 26
google-api-services-oauth2-v2-rev36-1.14.2-beta.jar com.google.apis:google-api-services-oauth2:v2-rev36-1.14.2-beta    0 26
platform-component-oauth-auth-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-oauth-auth:5.2.x-SNAPSHOT   0 26
pc-portlet-5.2.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-portlet:5.2.x-SNAPSHOT   0 29
gatein-cdi-injection-5.2.x-SNAPSHOT.jar org.gatein.cdi:gatein-cdi-injection:5.2.x-SNAPSHOT   0 29
gatein-cdi-contexts-5.2.x-SNAPSHOT.jar org.gatein.cdi:gatein-cdi-contexts:5.2.x-SNAPSHOT   0 27
platform-component-edition-community-5.2.x-SNAPSHOT.jar org.exoplatform.platform:platform-component-edition-community:5.2.x-SNAPSHOT   0 24
logback-core-1.1.2.jar cpe:/a:logback:logback:1.1.2 ch.qos.logback:logback-core:1.1.2  High 1 Low 30
commons-compiler-2.6.1.jar org.codehaus.janino:commons-compiler:2.6.1    0 18
janino-2.6.1.jar org.codehaus.janino:janino:2.6.1    0 21
plf-tomcat-integration-webapp-5.2.x-SNAPSHOT.war org.exoplatform.platform.distributions:plf-tomcat-integration-webapp:5.2.x-SNAPSHOT   0 26
plf-tomcat-pc-creator-listener-5.2.x-SNAPSHOT.jar org.exoplatform.platform.distributions:plf-tomcat-pc-creator-listener:5.2.x-SNAPSHOT   0 28
jansi-1.11.jar org.fusesource.jansi:jansi:1.11    0 24
hsqldb-2.4.0.jar org.hsqldb:hsqldb:2.4.0    0 35
jul-to-slf4j-1.7.7.jar org.slf4j:jul-to-slf4j:1.7.7    0 30
log4j-over-slf4j-1.7.7.jar org.slf4j:log4j-over-slf4j:1.7.7    0 29
liquibase-slf4j-2.0.0.jar cpe:/a:slf4j:slf4j-ext:2.0.0 com.mattbertolini:liquibase-slf4j:2.0.0    0 Low 24
snakeyaml-1.13.jar org.yaml:snakeyaml:1.13    0 25
plf-exo-tools-5.2.x-SNAPSHOT.jar cpe:/a:form_tools:form_tools:5.2 org.exoplatform.platform.distributions:plf-exo-tools:5.2.x-SNAPSHOT   0 Low 26
exo-lgpl-license-resource-bundle-2.jar org.exoplatform.resources:exo-lgpl-license-resource-bundle:2   0 27
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar cpe:/a:form_manager_project:form_manager:1.4   0 Low 15
jcr-parent-5.2.x-SNAPSHOT-source-release.zip: standard.jar cpe:/a:apache:standard_taglibs:1.1.2 taglibs:standard:1.1.2  High 1 Low 23
jcr-parent-5.2.x-SNAPSHOT-source-release.zip: jstl.jar jstl:jstl:1.1.2    0 24
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar: jansi.dll   0 2
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar: jansi.dll   0 2
jython-standalone-2.5.4-rc1.jar: wininst-7.1.exe   0 4
jython-standalone-2.5.4-rc1.jar: wininst-6.exe   0 4
jython-standalone-2.5.4-rc1.jar: jffi-1.0.dll   0 4
jython-standalone-2.5.4-rc1.jar: jffi-1.0.dll   0 4
jython-standalone-2.5.4-rc1.jar: jline32.dll   0 4
jython-standalone-2.5.4-rc1.jar: jline64.dll   0 4
ehcache-core-2.6.9.jar: sizeof-agent.jar net.sf.ehcache:sizeof-agent:1.0.1   0 26
smartgwt-lgpl-6.0-p20170514.jar: isomorphic_applets.jar   0 9
exo.portal.gadgets-server-5.2.x-SNAPSHOT.war: jcr-1.0.jar cpe:/a:content_project:content:1.0 javax.jcr:jcr:1.0  Medium 1 Low 31
exo.portal.gadgets-server-5.2.x-SNAPSHOT.war: slf4j-api-1.7.5.jar org.slf4j:slf4j-api:1.7.5    0 30
tomcat-8.5.35.zip: taglibs-standard-impl-1.2.5.jar cpe:/a:apache:standard_taglibs:1.2.5 org.apache.taglibs:taglibs-standard-impl:1.2.5    0 Low 28
tomcat-8.5.35.zip: sample.war   0 8
tomcat-8.5.35.zip: bootstrap.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
High 3 Low 12
tomcat-8.5.35.zip: commons-daemon.jar cpe:/a:apache:apache_commons_daemon:1.1.0 commons-daemon:commons-daemon:1.1.0    0 Low 39
tomcat-8.5.35.zip: websocket-api.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-websocket-api:8.5.35  High 3 Low 21
tomcat-8.5.35.zip: jasper.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-jasper:8.5.35  High 3 Low 24
tomcat-8.5.35.zip: catalina-ha.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-catalina-ha:8.5.35  High 3 Low 24
tomcat-8.5.35.zip: tomcat-i18n-fr.jar cpe:/a:apache_software_foundation:tomcat:8.5.35
cpe:/a:apache:tomcat:8.5.35
cpe:/a:apache_tomcat:apache_tomcat:8.5.35
org.apache.tomcat:tomcat-i18n-fr:8.5.35  High 3 Low 19
tomcat-8.5.35.zip: ecj-4.6.3.jar org.eclipse.jdt:ecj:3.12.3    0 32
jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml/pom.xml cpe:/a:fasterxml:jackson:2.4.2 com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.4.2   0 Low 16
jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/org.yaml/snakeyaml/pom.xml org.yaml:snakeyaml:1.12   0 11
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml org.jboss.marshalling:jboss-marshalling:2.0.0.Beta3   0 13
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml org.jboss.marshalling:jboss-marshalling-river:2.0.0.Beta3   0 13
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml org.jboss.marshalling:jboss-marshalling-serial:2.0.0.Beta3   0 13
jython-standalone-2.5.4-rc1.jar/META-INF/maven/jline/jline/pom.xml jline:jline:0.9.95-SNAPSHOT   0 11
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.antlr/antlr-runtime/pom.xml org.antlr:antlr-runtime:3.1.3   0 15
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.ext.posix/jnr-posix/pom.xml cpe:/a:jruby:jruby:1.1.4 org.jruby.ext.posix:jnr-posix:1.1.4 High 3 Highest 9
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/constantine/pom.xml cpe:/a:values_project:values:0.7 org.jruby.extras:constantine:0.7   0 Low 11
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jaffl/pom.xml org.jruby.extras:jaffl:0.5.1   0 11
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jffi/pom.xml cpe:/a:jruby:jruby:1.0.1 org.jruby.extras:jffi:1.0.1 High 3 Highest 11
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jnr-netdb/pom.xml org.jruby.extras:jnr-netdb:0.4   0 11
hibernate-validator-4.2.0.Final.jar/META-INF/maven/com.googlecode.jtype/jtype/pom.xml com.googlecode.jtype:jtype:0.1.1   0 12
jansi-1.11.jar/META-INF/maven/org.fusesource.hawtjni/hawtjni-runtime/pom.xml org.fusesource.hawtjni:hawtjni-runtime:1.8   0 13
jansi-1.11.jar/META-INF/maven/org.fusesource.jansi/jansi-native/pom.xml cpe:/a:id:id-software:1.5 org.fusesource.jansi:jansi-native:1.5   0 Low 16
jansi-1.11.jar/META-INF/maven/org.fusesource.jansi/jansi/pom.xml cpe:/a:id:id-software:1.11 org.fusesource.jansi:jansi:1.11   0 Low 13
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar/META-INF/maven/com.beust/jcommander/pom.xml com.beust:jcommander:1.35   0 11
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar/META-INF/maven/jline/jline/pom.xml jline:jline:2.12   0 7
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar/META-INF/maven/org.eclipse.aether/aether-api/pom.xml org.eclipse.aether:aether-api:1.1.0   0 13
addons-manager-1.4.x-SNAPSHOT.zip: addons-manager.jar/META-INF/maven/org.eclipse.aether/aether-util/pom.xml org.eclipse.aether:aether-util:1.1.0   0 13

Dependencies

tomcat-juli-8.5.35.jar

Description: Tomcat Core Logging Package

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/tomcat-juli/8.5.35/tomcat-juli-8.5.35.jar
MD5: c3b6b2bc241e6572ada480e972702800
SHA1: 69d0606072b31b57ba706d1ffc102064ad8f694b
Referenced In Project/Scope: eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:provided

Identifiers

tomcat-api-8.5.35.jar

Description: Definition of interfaces shared by Catalina and Jasper

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/tomcat-api/8.5.35/tomcat-api-8.5.35.jar
MD5: 589ecb726f3bc8232d6618e97740dc40
SHA1: cdfda95188ce0322becbef1da00f2ec24c73a44b
Referenced In Project/Scope: eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:provided

Identifiers

CVE-2016-5425  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2016-6325  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2017-6056  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.

Vulnerable Software & Versions:

tomcat-jni-8.5.35.jar

Description: Interface code to the native connector

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/tomcat-jni/8.5.35/tomcat-jni-8.5.35.jar
MD5: 8fb29c42b9ff472d8fc78d9f3c320215
SHA1: 23dfd85acc1bccf73a0b1e7822fd1b898c4719a6
Referenced In Project/Scope: eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:provided

Identifiers

  • maven: org.apache.tomcat:tomcat-jni:8.5.35    Confidence:Highest
  • cpe: cpe:/a:apache:tomcat_native:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache_software_foundation:tomcat:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache:tomcat:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache_tomcat:apache_tomcat:8.5.35   Confidence:Low   

CVE-2016-5425  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2016-6325  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2017-6056  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.

Vulnerable Software & Versions:

tomcat-coyote-8.5.35.jar

Description: Tomcat Connectors and HTTP parser

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/tomcat-coyote/8.5.35/tomcat-coyote-8.5.35.jar
MD5: 53791305852201a76cb079c2f49918f5
SHA1: da94c8aa9c321d79372657103693da3c1729dbee
Referenced In Project/Scope: eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:provided

Identifiers

  • maven: org.apache.tomcat:tomcat-coyote:8.5.35    Confidence:Highest
  • cpe: cpe:/a:apache:coyote_http_connector:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache_software_foundation:tomcat:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache:tomcat:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache:tomcat_connectors:8.5.35   Confidence:Low   
  • cpe: cpe:/a:apache_tomcat:apache_tomcat:8.5.35   Confidence:Low   

CVE-2016-5425  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2016-6325  

Severity: High
CVSS Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

Vulnerable Software & Versions:

CVE-2017-6056  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.

Vulnerable Software & Versions:

mime-util-2.1.3.jar

Description: mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/eu/medsea/mimeutil/mime-util/2.1.3/mime-util-2.1.3.jar
MD5: 3d4f3e1a96eb79683197f1c8b182f4a6
SHA1: 0c9cfae15c74f62491d4f28def0dff1dabe52a47
Referenced In Projects/Scopes:
  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

jakarta-regexp-1.4.jar

File Path: /home/ciagent/.m2/repository/jakarta-regexp/jakarta-regexp/1.4/jakarta-regexp-1.4.jar
MD5: 5d8b8c601c21b37aa6142d38f45c0297
SHA1: 0ea514a179ac1dd7e81c7e6594468b9b9910d298
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

xpp3-1.1.6.jar

Description: XML Pull parser library developed by Extreme Computing Lab, Indiana University

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ogce/xpp3/1.1.6/xpp3-1.1.6.jar
MD5: 626a429318310e92e3466151e050bdc5
SHA1: dc87e00ddb69341b46a3eb1c331c6fcebf6c8546
Referenced In Projects/Scopes:
  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

jcl-over-slf4j-1.7.7.jar

Description: JCL 1.1.1 implemented over SLF4J

File Path: /home/ciagent/.m2/repository/org/slf4j/jcl-over-slf4j/1.7.7/jcl-over-slf4j-1.7.7.jar
MD5: 32ad130f946ef0460af416397b7fc7b7
SHA1: 56003dcd0a31deea6391b9e2ef2f2dc90b205a92
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

slf4j-api-1.7.7.jar

Description: The slf4j API

File Path: /home/ciagent/.m2/repository/org/slf4j/slf4j-api/1.7.7/slf4j-api-1.7.7.jar
MD5: ca4280bf93d64367723ae5c8d42dd0b9
SHA1: 2b8019b6249bb05d81d3a3094e468753e2b21311
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

exo.kernel.commons-5.2.x-SNAPSHOT.jar

Description: Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.commons/5.2.x-SNAPSHOT/exo.kernel.commons-5.2.x-SNAPSHOT.jar
MD5: 32f3e3030115ff5f49339f43cbf27eae
SHA1: c0ea42d7a974d853aaf2ed2124e90c84431dc2ae
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

  • maven: org.exoplatform.kernel:exo.kernel.commons:5.2.x-SNAPSHOT   Confidence:High

commons-beanutils-1.8.3.jar

Description: BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-beanutils/commons-beanutils/1.8.3/commons-beanutils-1.8.3.jar
MD5: b45be74134796c89db7126083129532f
SHA1: 686ef3410bcf4ab8ce7fd0b899e832aaba5facf7
Referenced In Projects/Scopes:
  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided

Identifiers

CVE-2014-0114  

Severity: High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

Vulnerable Software & Versions: (show all)

common-common-2.2.2.Final.jar

File Path: /home/ciagent/.m2/repository/org/gatein/common/common-common/2.2.2.Final/common-common-2.2.2.Final.jar
MD5: 8ce16b5e3991285cd27e553740d09d1f
SHA1: 44522d899e31a5a10dbd70f7b0ca2fe5a614f740
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided
  • eXo PLF:: Platform Public Distributions - Tomcat Integration WebApp:compile

Identifiers

wci-wci-5.2.x-SNAPSHOT.jar

File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/wci/wci-wci/5.2.x-SNAPSHOT/wci-wci-5.2.x-SNAPSHOT.jar
MD5: 9be7f8aea19a80a647423fa43a36c72b
SHA1: 7c6923487afec73cb54ed4e7cca915b5f8cba968
Referenced In Projects/Scopes:

  • eXo PLF:: Platform Public Distributions - Tomcat Portal Containers Creator:compile
  • eXo PLF:: Platform Public Distributions - Dependencies:compile
  • eXo PLF:: Platform Public Distributions - Tomcat Resources:compile
  • eXo PLF:: Platform Public Distributions - Community Tomcat Standalone:provided
  • eXo PLF:: Platform Public Distributions - Tomcat Integration WebApp:compile

Identifiers

  • maven: org.exoplatform.gatein.wci:wci-wci:5.2.x-SNAPSHOT   Confidence:High

jibx-run-1.2.6.jar

Description: JiBX runtime code