Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.1Report Generated On : Sat, 10 Apr 2021 11:06:15 +0200Dependencies Scanned : 145 (82 unique)Vulnerable Dependencies : 12 Vulnerabilities Found : 29Vulnerabilities Suppressed : 0... NVD CVE Checked : 2021-04-10T10:56:40NVD CVE Modified : 2021-04-10T02:01:43VersionCheckOn : 2021-03-15T17:11:58Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies activation-1.1.1.jarDescription:
The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/javax/activation/activation/1.1.1/activation-1.1.1.jar
MD5: 46a37512971d8eca81c3fcf245bf07d2
SHA1: 485de3a253e23f645037828c07f1d7f1af40763a
SHA256: ae475120e9fcd99b4b00b38329bd61cdc5eb754eee03fe66c01f50e137724f99
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor file name activation High Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor jar package name sun Highest Vendor pom artifactid activation Low Vendor pom groupid javax.activation Highest Vendor pom name JavaBeans(TM) Activation Framework High Vendor pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Highest Vendor jar package name activation Highest Vendor jar package name javax Highest Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Product file name activation High Product pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Medium Product jar package name activation Highest Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium Product jar package name javax Highest Product Manifest extension-name javax.activation Medium Product pom artifactid activation Highest Product pom groupid javax.activation Highest Product pom name JavaBeans(TM) Activation Framework High Version Manifest Implementation-Version 1.1.1 High Version pom version 1.1.1 Highest Version file version 1.1.1 High
aspectjrt-1.9.6.jarDescription:
The runtime needed to execute a program using AspectJ License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/aspectj/aspectjrt/1.9.6/aspectjrt-1.9.6.jar
MD5: 391f9257f19b84b45eb79a1878b9600a
SHA1: 1651849d48659e5703adc2599e694bf67b8c3fc4
SHA256: 20c785678cbb4ee045914daf83da25f98a16071177dfa0e3451326723dfb4705
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name runtime Highest Vendor manifest: org/aspectj/lang/ Implementation-Vendor https://www.eclipse.org/aspectj/ Medium Vendor pom artifactid aspectjrt Low Vendor Manifest automatic-module-name org.aspectj.runtime Medium Vendor jar package name aspectj Highest Vendor pom name AspectJ runtime High Vendor file name aspectjrt High Vendor pom groupid org.aspectj Highest Vendor pom groupid aspectj Highest Vendor pom url https://www.eclipse.org/aspectj/ Highest Product pom url https://www.eclipse.org/aspectj/ Medium Product jar package name runtime Highest Product manifest: org/aspectj/lang/ Specification-Title AspectJ Runtime Classes Medium Product Manifest automatic-module-name org.aspectj.runtime Medium Product jar package name aspectj Highest Product pom name AspectJ runtime High Product file name aspectjrt High Product manifest: org/aspectj/lang/ Implementation-Title org.aspectj.runtime Medium Product pom groupid aspectj Highest Product pom artifactid aspectjrt Highest Version manifest: org/aspectj/lang/ Implementation-Version 1.9.6 Medium Version pom version 1.9.6 Highest Version file version 1.9.6 High
cling-core-2.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/fourthline/cling/cling-core/2.1.1/cling-core-2.1.1.jarMD5: 54a3af9ee2022ec78ee3a00c152a7af0SHA1: 767954a4d738b8c77606d19a6c0255193651ccbaSHA256: 435497b9c1d768a220d366bc98f37a2d86469dcfaec7ff8ddb46a18384748128Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name fourthline Highest Vendor pom parent-groupid org.fourthline.cling Medium Vendor pom groupid org.fourthline.cling Highest Vendor jar package name fourthline Low Vendor pom groupid fourthline.cling Highest Vendor jar package name cling Low Vendor jar package name cling Highest Vendor pom artifactid cling-core Low Vendor pom parent-artifactid cling Low Vendor file name cling-core High Vendor pom name Cling Core High Product pom parent-artifactid cling Medium Product jar package name fourthline Highest Product pom parent-groupid org.fourthline.cling Medium Product pom artifactid cling-core Highest Product pom groupid fourthline.cling Highest Product jar package name cling Low Product jar package name cling Highest Product file name cling-core High Product pom name Cling Core High Version file version 2.1.1 High Version pom version 2.1.1 Highest
cling-support-2.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/fourthline/cling/cling-support/2.1.1/cling-support-2.1.1.jarMD5: 84f5b91563f5c05f1f48b2c9ccb67402SHA1: 4b24a331452a3b4b078954490bf7430459495f6cSHA256: c8abb2925e371cd8baffff2fb07316f8d3a4723e7903280cf46323f884967946Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name fourthline Highest Vendor pom groupid org.fourthline.cling Highest Vendor jar package name fourthline Low Vendor pom artifactid cling-support Low Vendor pom parent-groupid org.fourthline.cling Medium Vendor pom name Cling Support High Vendor jar package name support Highest Vendor jar package name support Low Vendor file name cling-support High Vendor pom groupid fourthline.cling Highest Vendor jar package name cling Low Vendor jar package name cling Highest Vendor pom parent-artifactid cling Low Product pom parent-artifactid cling Medium Product jar package name fourthline Highest Product pom parent-groupid org.fourthline.cling Medium Product pom name Cling Support High Product jar package name support Highest Product jar package name support Low Product file name cling-support High Product pom groupid fourthline.cling Highest Product jar package name cling Low Product pom artifactid cling-support Highest Product jar package name cling Highest Version file version 2.1.1 High Version pom version 2.1.1 Highest
commons-codec-1.10.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
SHA256: 4241dfa94e711d435f29a4604a3e2de5c4aa3c165e23bd066be6fc1fc4309569
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name codec Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest Vendor jar package name commons Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom groupid commons-codec Highest Vendor file name commons-codec High Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name apache Highest Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium Vendor pom artifactid commons-codec Low Vendor pom name Apache Commons Codec High Vendor jar package name encoder Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low Product pom artifactid commons-codec Highest Product pom parent-artifactid commons-parent Medium Product jar package name codec Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low Product pom url http://commons.apache.org/proper/commons-codec/ Medium Product Manifest Bundle-Name Apache Commons Codec Medium Product jar package name commons Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom groupid commons-codec Highest Product file name commons-codec High Product pom parent-groupid org.apache.commons Medium Product Manifest Implementation-Title Apache Commons Codec High Product jar package name apache Highest Product Manifest bundle-symbolicname org.apache.commons.codec Medium Product jar package name encoder Highest Product pom name Apache Commons Codec High Product Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low Product Manifest specification-title Apache Commons Codec Medium Version pom parent-version 1.10 Low Version pom version 1.10 Highest Version file version 1.10 High Version Manifest Implementation-Version 1.10 High
commons-io-2.4.jarDescription:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/commons-io/commons-io/2.4/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
SHA256: cc6a41dc3eaacc9e440a6bd0d2890b20d36b4ee408fe2d67122f328bb6e01581
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-io Low Vendor jar package name commons Highest Vendor pom name Commons IO High Vendor pom url http://commons.apache.org/io/ Highest Vendor jar package name io Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid commons-io Highest Vendor file name commons-io High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low Product pom url http://commons.apache.org/io/ Medium Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-io Highest Product Manifest bundle-docurl http://commons.apache.org/io/ Low Product Manifest bundle-symbolicname org.apache.commons.io Medium Product jar package name commons Highest Product pom name Commons IO High Product Manifest specification-title Commons IO Medium Product jar package name io Highest Product file name commons-io High Product pom groupid commons-io Highest Product Manifest Bundle-Name Commons IO Medium Product pom parent-groupid org.apache.commons Medium Product jar package name apache Highest Product Manifest Implementation-Title Commons IO High Product Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low Version pom version 2.4 Highest Version file version 2.4 High Version Manifest Implementation-Version 2.4 High Version pom parent-version 2.4 Low
commons-lang-2.6.jarDescription:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
SHA256: 50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom groupid commons-lang Highest Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium Vendor pom parent-artifactid commons-parent Low Vendor jar package name lang Highest Vendor jar package name commons Highest Vendor file name commons-lang High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom url http://commons.apache.org/lang/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name apache Highest Vendor pom name Commons Lang High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid commons-lang Low Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-lang Highest Product pom url http://commons.apache.org/lang/ Medium Product Manifest Implementation-Title Commons Lang High Product Manifest bundle-symbolicname org.apache.commons.lang Medium Product pom groupid commons-lang Highest Product jar package name lang Highest Product jar package name commons Highest Product file name commons-lang High Product Manifest Bundle-Name Commons Lang Medium Product pom parent-groupid org.apache.commons Medium Product jar package name apache Highest Product Manifest specification-title Commons Lang Medium Product pom name Commons Lang High Product Manifest bundle-docurl http://commons.apache.org/lang/ Low Version Manifest Bundle-Version 2.6 High Version pom version 2.6 Highest Version Manifest Implementation-Version 2.6 High Version file version 2.6 High Version pom parent-version 2.6 Low
commons-lang3-3.5.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/commons/commons-lang3/3.5/commons-lang3-3.5.jar
MD5: 780b5a8b72eebe6d0dbff1c11b5658fa
SHA1: 6c6c702c89bfff3cd9e80b04d668c5e190d588c6
SHA256: 8ac96fc686512d777fca85e144f196cd7cfe0c0aec23127229497d1a38ff651c
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom groupid org.apache.commons Highest Vendor pom artifactid commons-lang3 Low Vendor pom groupid apache.commons Highest Vendor pom name Apache Commons Lang High Vendor jar package name lang3 Highest Vendor pom parent-artifactid commons-parent Low Vendor jar package name commons Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name apache Highest Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest Vendor Manifest implementation-build release@r36f98d87b24c2f542b02abbf6ec1ee742f1b158b; 2016-10-13 19:52:17+0000 Low Vendor file name commons-lang3 High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-lang/ Medium Product pom groupid apache.commons Highest Product pom name Apache Commons Lang High Product pom artifactid commons-lang3 Highest Product jar package name lang3 Highest Product jar package name commons Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest specification-title Apache Commons Lang Medium Product Manifest Bundle-Name Apache Commons Lang Medium Product pom parent-groupid org.apache.commons Medium Product jar package name apache Highest Product Manifest implementation-build release@r36f98d87b24c2f542b02abbf6ec1ee742f1b158b; 2016-10-13 19:52:17+0000 Low Product Manifest Implementation-Title Apache Commons Lang High Product file name commons-lang3 High Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Version file version 3.5 High Version pom parent-version 3.5 Low Version pom version 3.5 Highest Version Manifest Implementation-Version 3.5 High
fluent-hc-4.5.2.jarDescription:
Apache HttpComponents Client fluent API
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/fluent-hc/4.5.2/fluent-hc-4.5.2.jarMD5: cf1dabb4e28eb4bef54a3dfd268a9e19SHA1: 7bfdfa49de6d720ad3c8cedb6a5238eec564dfedSHA256: f63f033bef4041274aab064ca63fc731298d579de7fd87c9cc1ca2c789717bb8Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor pom artifactid fluent-hc Low Vendor pom name Apache HttpClient Fluent API High Vendor Manifest implementation-build tags/4.5.2-RC1/fluent-hc@r1731537; 2016-02-21 17:03:53+0100 Low Vendor jar package name client Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid httpcomponents-client Low Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name fluent Highest Vendor file name fluent-hc High Vendor jar package name apache Highest Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Product jar package name http Highest Product Manifest specification-title HttpComponents Apache HttpClient Fluent API Medium Product pom name Apache HttpClient Fluent API High Product jar package name client Highest Product Manifest implementation-build tags/4.5.2-RC1/fluent-hc@r1731537; 2016-02-21 17:03:53+0100 Low Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product jar package name fluent Highest Product file name fluent-hc High Product jar package name apache Highest Product Manifest Implementation-Title HttpComponents Apache HttpClient Fluent API High Product pom groupid apache.httpcomponents Highest Product pom artifactid fluent-hc Highest Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom url http://hc.apache.org/httpcomponents-client Medium Version Manifest Implementation-Version 4.5.2 High Version pom version 4.5.2 Highest Version file version 4.5.2 High
Published Vulnerabilities CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
guava-18.0.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/google/guava/guava/18.0/guava-18.0.jar
MD5: 947641f6bb535b1d942d1bc387c45290
SHA1: cce0823396aa693798f8882e64213b1772032b09
SHA256: d664fbfc03d2e5ce9cab2a44fb01f1d0bf9dfebeccc1a473b1f9ea31f79f6f99
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.google.guava Highest Vendor pom parent-artifactid guava-parent Low Vendor pom name Guava: Google Core Libraries for Java High Vendor Manifest bundle-docurl https://guava-libraries.googlecode.com/ Low Vendor jar package name google Highest Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom parent-groupid com.google.guava Medium Vendor file name guava High Vendor pom groupid google.guava Highest Vendor pom artifactid guava Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Product Manifest bundle-docurl https://guava-libraries.googlecode.com/ Low Product jar package name google Highest Product pom parent-artifactid guava-parent Medium Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Medium Product file name guava High Product pom groupid google.guava Highest Version pom version 18.0 Highest Version file version 18.0 High
Published Vulnerabilities CVE-2018-10237 suppress
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MLIST - [activemq-gitbox] 20190530 [GitHub] [activemq-artemis] brusdev opened a new pull request #2687: ARTEMIS-2359 Upgrade to Guava 24.1 MLIST - [activemq-issues] 20190516 [jira] [Created] (AMQ-7208) Security Issue related to Guava 18.0 MLIST - [activemq-issues] 20190820 [jira] [Created] (AMQ-7279) Security Vulnerabilities in Libraries - jackson-databind-2.9.8.jar, tomcat-servlet-api-8.0.53.jar, tomcat-websocket-api-8.0.53.jar, zookeeper-3.4.6.jar, guava-18.0.jar, jetty-all-9.2.26.v20180806.jar, scala-library-2.11.0.jar MLIST - [cassandra-commits] 20190612 [jira] [Assigned] (CASSANDRA-14760) CVE-2018-10237 Security vulnerability in 3.11.3 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] davidkarlsen opened a new pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200211 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] andrei-ivanov commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [drill-dev] 20191017 Dependencies used by Drill contain known vulnerabilities MLIST - [drill-dev] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [drill-issues] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [flink-dev] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [flink-dev] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200814 [jira] [Commented] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20210212 [jira] [Closed] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-user] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [hadoop-common-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [hadoop-common-dev] 20200623 Update guava to 27.0-jre in hadoop branch-2.10 MLIST - [hadoop-hdfs-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [kafka-users] 20200413 CVEs for the dependency software guava and rocksdbjni of Kafka MLIST - [lucene-issues] 20201022 [jira] [Created] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Resolved] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Updated] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [maven-issues] 20210122 [GitHub] [maven-indexer] akurtakov opened a new pull request #75: Remove guava dependency from indexer-core MLIST - [pulsar-commits] 20190416 [GitHub] [pulsar] one70six opened a new issue #4057: Security Vulnerabilities - Black Duck Scan - Pulsar v.2.3.1 MLIST - [pulsar-commits] 20210406 [GitHub] [pulsar] lhotari opened a new pull request #10149: Upgrade jclouds to 2.3.0 to fix security vulnerabilities MLIST - [samza-commits] 20210310 [GitHub] [samza] Telesia opened a new pull request #1471: SAMZA-2630: Upgrade dependencies for security fixes MLIST - [storm-issues] 20210315 [jira] [Created] (STORM-3754) Upgrade Guava version because of security vulnerability MLIST - [syncope-dev] 20200423 Re: Time to cut 2.1.6 / 2.0.15? N/A - N/A OSSINDEX - [CVE-2018-10237] Deserialization of Untrusted Data REDHAT - RHSA-2018:2423 REDHAT - RHSA-2018:2424 REDHAT - RHSA-2018:2425 REDHAT - RHSA-2018:2428 REDHAT - RHSA-2018:2598 REDHAT - RHSA-2018:2643 REDHAT - RHSA-2018:2740 REDHAT - RHSA-2018:2741 REDHAT - RHSA-2018:2742 REDHAT - RHSA-2018:2743 REDHAT - RHSA-2018:2927 REDHAT - RHSA-2019:2858 REDHAT - RHSA-2019:3149 SECTRACK - 1041707 Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
httpclient-4.4.jarDescription:
Apache HttpComponents Client
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpclient/4.4/httpclient-4.4.jarMD5: ccf9833ec0cbd38831ceeb8fc246e2ddSHA1: 6d220441ca681dddc55a189eae81a437309128b8SHA256: c50eafa5477af2fa8217d3f729b815ff3c669dbc467552c0feeedc61be965523Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor jar package name httpclient Highest Vendor Manifest implementation-build tags/4.4-RC2/httpclient@r1655155; 2015-01-27 21:56:00+0100 Low Vendor jar package name client Highest Vendor file name httpclient High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid httpcomponents-client Low Vendor pom name Apache HttpClient High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name apache Highest Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom artifactid httpclient Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Product jar package name http Highest Product pom artifactid httpclient Highest Product jar package name httpclient Highest Product Manifest implementation-build tags/4.4-RC2/httpclient@r1655155; 2015-01-27 21:56:00+0100 Low Product jar package name client Highest Product file name httpclient High Product Manifest specification-title HttpComponents Apache HttpClient Medium Product pom name Apache HttpClient High Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product Manifest Implementation-Title HttpComponents Apache HttpClient High Product jar package name apache Highest Product pom groupid apache.httpcomponents Highest Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom url http://hc.apache.org/httpcomponents-client Medium Version Manifest Implementation-Version 4.4 High Version pom version 4.4 Highest Version file version 4.4 High
Related Dependencies httpclient-cache-4.4.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpclient-cache/4.4/httpclient-cache-4.4.jar MD5: b13aaf8efc362ca9bd4e5ee7cfbc7080 SHA1: d9e249ad4b19cb8ef7d45e8fe6dda49cdd4aa123 SHA256: 03e11fd5064da2afc3d27ce480275c3d4a28f5781745a46b48bd1a4cc346046a pkg:maven/org.apache.httpcomponents/httpclient-cache@4.4 Published Vulnerabilities CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
httpclient-osgi-4.5.2.jarDescription:
Apache HttpComponents Client
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpclient-osgi/4.5.2/httpclient-osgi-4.5.2.jar
MD5: 59c3fe979bf2cd795786bf28373b43f6
SHA1: 3262c30d156f3ae05a5c95d9aa39f0e3eed17585
SHA256: de3ec9919ab0d3263fb1c993ceb1d1aba29dba33a26f8aaf0c3679cc8348beea
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid httpclient-osgi Low Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor jar package name httpclient Highest Vendor jar package name client Highest Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2016-02-21 17:03:53+0100 Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name osgi Highest Vendor pom parent-artifactid httpcomponents-client Low Vendor pom name Apache HttpClient High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.httpcomponents.httpclient Medium Vendor jar package name apache Highest Vendor pom name Apache HttpClient OSGi bundle High Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom artifactid httpclient Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name httpclient-osgi High Product jar package name http Highest Product pom artifactid httpclient Highest Product jar package name httpclient Highest Product pom artifactid httpclient-osgi Highest Product jar package name client Highest Product jar package name osgi Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2016-02-21 17:03:53+0100 Low Product Manifest specification-title HttpComponents Apache HttpClient OSGi bundle Medium Product pom name Apache HttpClient High Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product Manifest Bundle-Name Apache Apache HttpClient OSGi bundle Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product jar package name apache Highest Product Manifest bundle-symbolicname org.apache.httpcomponents.httpclient Medium Product pom name Apache HttpClient OSGi bundle High Product Manifest Implementation-Title HttpComponents Apache HttpClient OSGi bundle High Product pom groupid apache.httpcomponents Highest Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom url http://hc.apache.org/httpcomponents-client Medium Product file name httpclient-osgi High Version Manifest Bundle-Version 4.5.2 High Version Manifest Implementation-Version 4.5.2 High Version pom version 4.5.2 Highest Version file version 4.5.2 High
Published Vulnerabilities CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
httpclient-osgi-4.5.2.jar (shaded: commons-codec:commons-codec:1.9)Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpclient-osgi/4.5.2/httpclient-osgi-4.5.2.jar/META-INF/maven/commons-codec/commons-codec/pom.xmlMD5: 921b8b50ce6dc0c5a8605d7c7011bd37SHA1: f5357ff0f308600af3660bf00a8be3415a335723SHA256: e5efcf039cd909688c201dc5479b144fd6f01f0e40252b7fc5e7d2e1b5c07990Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid commons-codec Highest Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest Vendor pom artifactid commons-codec Low Vendor pom name Apache Commons Codec High Product pom artifactid commons-codec Highest Product pom parent-artifactid commons-parent Medium Product pom groupid commons-codec Highest Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-codec/ Medium Product pom name Apache Commons Codec High Version pom version 1.9 Highest Version pom parent-version 1.9 Low
httpclient-osgi-4.5.2.jar (shaded: org.apache.httpcomponents:httpclient-cache:4.5.2)Description:
Apache HttpComponents HttpClient - Cache
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpclient-osgi/4.5.2/httpclient-osgi-4.5.2.jar/META-INF/maven/org.apache.httpcomponents/httpclient-cache/pom.xmlMD5: b19b9eca8a6d93f431eb48f0dbd1fb57SHA1: b51afa5f36dd4f0b2d7e87867a646a34ab690c96SHA256: 8ed51e8da875c225f5417db283e61f0d2817959f8564a99a5c4e90113aef32d2Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor pom name Apache HttpClient Cache High Vendor pom artifactid httpclient-cache Low Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-artifactid httpcomponents-client Low Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product pom artifactid httpclient-cache Highest Product pom name Apache HttpClient Cache High Product pom groupid apache.httpcomponents Highest Product pom url http://hc.apache.org/httpcomponents-client Medium Version pom version 4.5.2 Highest
Published Vulnerabilities CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
httpcore-4.4.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpcore/4.4/httpcore-4.4.jarMD5: e016cf1346ba3f65302c3d71c5b91f44SHA1: e9b3863fd9c8a273ceed4a7fae10f40bb10a2328SHA256: 1ef8db5d30b7741ab5fdf6df876a090a7dd51623e83f3736d0bb8fb1b5ead32fReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid httpcomponents-core Low Vendor pom name Apache HttpCore High Vendor pom artifactid httpcore Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor jar package name apache Highest Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor file name httpcore High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build tags/4.4-RC1/httpcore@r1645448; 2014-12-14 13:29:59+0100 Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product jar package name http Highest Product pom artifactid httpcore Highest Product pom name Apache HttpCore High Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-core Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product jar package name apache Highest Product pom groupid apache.httpcomponents Highest Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product file name httpcore High Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-build tags/4.4-RC1/httpcore@r1645448; 2014-12-14 13:29:59+0100 Low Version Manifest Implementation-Version 4.4 High Version pom version 4.4 Highest Version file version 4.4 High
httpcore-nio-4.4.4.jarDescription:
Apache HttpComponents Core (non-blocking I/O)
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpcore-nio/4.4.4/httpcore-nio-4.4.4.jarMD5: 562f930326530c262c04d7b4f6b1d055SHA1: 16badfc2d99db264c486ba8c57ae577301a58bd9SHA256: f21be11ed00a7c655204c03d3ff38c2e8ac88db0913da3598ce5f9ffd686ae1fReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build tags/4.4.4-RC1/httpcore-nio@r1710658; 2015-10-26 18:15:56+0100 Low Vendor pom parent-artifactid httpcomponents-core Low Vendor jar package name nio Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Apache HttpCore NIO High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor file name httpcore-nio High Vendor jar package name apache Highest Vendor pom artifactid httpcore-nio Low Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product pom artifactid httpcore-nio Highest Product jar package name http Highest Product Manifest implementation-build tags/4.4.4-RC1/httpcore-nio@r1710658; 2015-10-26 18:15:56+0100 Low Product jar package name nio Highest Product pom name Apache HttpCore NIO High Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-core Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product file name httpcore-nio High Product Manifest specification-title HttpComponents Apache HttpCore NIO Medium Product jar package name apache Highest Product pom groupid apache.httpcomponents Highest Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product Manifest Implementation-Title HttpComponents Apache HttpCore NIO High Version pom version 4.4.4 Highest Version file version 4.4.4 High Version Manifest Implementation-Version 4.4.4 High
httpcore-osgi-4.4.4.jarDescription:
Apache HttpComponents Core (blocking I/O)
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpcore-osgi/4.4.4/httpcore-osgi-4.4.4.jar
MD5: a667179ec81d755e6455ffe6cc5276e8
SHA1: d5c14055e569afca96f4603d6f9d467bc72ccba8
SHA256: a0bd904e00cb6788efd5cd8c180cb19569bba43e22a711e9b020ffa51b045a4c
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2015-10-26 18:15:56+0100 Low Vendor pom parent-artifactid httpcomponents-core Low Vendor pom artifactid httpcore-osgi Low Vendor file name httpcore-osgi High Vendor Manifest bundle-symbolicname org.apache.httpcomponents.httpcore Medium Vendor pom name Apache HttpCore High Vendor pom name Apache HttpCore OSGi bundle High Vendor pom artifactid httpcore Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor jar package name apache Highest Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2015-10-26 18:15:56+0100 Low Product jar package name http Highest Product file name httpcore-osgi High Product pom artifactid httpcore Highest Product Manifest bundle-symbolicname org.apache.httpcomponents.httpcore Medium Product pom name Apache HttpCore High Product pom name Apache HttpCore OSGi bundle High Product Manifest Implementation-Title HttpComponents Apache HttpCore OSGi bundle High Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-core Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product jar package name apache Highest Product Manifest specification-title HttpComponents Apache HttpCore OSGi bundle Medium Product Manifest Bundle-Name Apache Apache HttpCore OSGi bundle Medium Product pom groupid apache.httpcomponents Highest Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product pom artifactid httpcore-osgi Highest Version pom version 4.4.4 Highest Version file version 4.4.4 High Version Manifest Bundle-Version 4.4.4 High Version Manifest Implementation-Version 4.4.4 High
httpmime-4.5.2.jarDescription:
Apache HttpComponents HttpClient - MIME coded entities
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/apache/httpcomponents/httpmime/4.5.2/httpmime-4.5.2.jarMD5: 336fa980f7527be719fa997f5df8046fSHA1: 22b4c53dd9b6761024258de8f9240c3dce6ea368SHA256: 231a3f7e4962053db2be8461d5422e68fc458a3a7dd7d8ada803a348e21f8f07Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor pom artifactid httpmime Low Vendor pom name Apache HttpClient Mime High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest implementation-build tags/4.5.2-RC1/httpmime@r1731537; 2016-02-21 17:03:53+0100 Low Vendor pom parent-artifactid httpcomponents-client Low Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name apache Highest Vendor pom groupid apache.httpcomponents Highest Vendor pom groupid org.apache.httpcomponents Highest Vendor file name httpmime High Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name mime Highest Product pom artifactid httpmime Highest Product jar package name http Highest Product Manifest specification-title HttpComponents Apache HttpClient Mime Medium Product pom name Apache HttpClient Mime High Product Manifest implementation-build tags/4.5.2-RC1/httpmime@r1731537; 2016-02-21 17:03:53+0100 Low Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product Manifest Implementation-Title HttpComponents Apache HttpClient Mime High Product jar package name apache Highest Product pom groupid apache.httpcomponents Highest Product file name httpmime High Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom url http://hc.apache.org/httpcomponents-client Medium Product jar package name mime Highest Version Manifest Implementation-Version 4.5.2 High Version pom version 4.5.2 Highest Version file version 4.5.2 High
it-tidalwave-bluemarine2-catalog-1.1-ALPHA-1.jarDescription:
The implementation of the media catalog.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-catalog/1.1-ALPHA-1/it-tidalwave-bluemarine2-catalog-1.1-ALPHA-1.jarMD5: d491adf243cb25507e81efd7140a0eceSHA1: 064ff3d421935cfd4f1fd0bd35e2e8801e96d890SHA256: 7ce7fd8c02097f8f38606b7f6cb0165fcfc0eff61fd2f4d5b7374ae3ce274475Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name it-tidalwave-bluemarine2-catalog High Vendor jar package name tidalwave Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom artifactid it-tidalwave-bluemarine2-catalog Low Vendor pom parent-artifactid bluemarine2-modules Low Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor pom name blueMarine II :: Catalog High Product pom parent-artifactid bluemarine2-modules Medium Product file name it-tidalwave-bluemarine2-catalog High Product Manifest specification-title blueMarine II :: Catalog Medium Product jar package name tidalwave Highest Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product Manifest Implementation-Title blueMarine II :: Catalog High Product pom artifactid it-tidalwave-bluemarine2-catalog Highest Product pom name blueMarine II :: Catalog High Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-commons-1.1-ALPHA-1.jarDescription:
Utility code that is common to the whole project.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-commons/1.1-ALPHA-1/it-tidalwave-bluemarine2-commons-1.1-ALPHA-1.jarMD5: d450852502b7d426979a720126db986dSHA1: 555bac8561a9f0bdd8da3ab174f13cd1db500ad8SHA256: cdd10c81760079227e642bf9693cfd01c6c621f574adcd2b7531985fd9322a3aReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name tidalwave Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor pom artifactid it-tidalwave-bluemarine2-commons Low Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor file name it-tidalwave-bluemarine2-commons High Vendor pom parent-artifactid bluemarine2-modules Low Vendor pom name blueMarine II :: Commons High Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product Manifest Implementation-Title blueMarine II :: Commons High Product file name it-tidalwave-bluemarine2-commons High Product pom name blueMarine II :: Commons High Product pom artifactid it-tidalwave-bluemarine2-commons Highest Product Manifest specification-title blueMarine II :: Commons Medium Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-downloader-1.1-ALPHA-1.jarDescription:
The component that is capable to download stuff from the internet.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-downloader/1.1-ALPHA-1/it-tidalwave-bluemarine2-downloader-1.1-ALPHA-1.jarMD5: f190ee3dd6ed780dca8a37c13981fa6dSHA1: 1e1074a650f09e4d78b3d20762302eb94d1def85SHA256: 72c85e4b418c700e83dc2115082d5ffe95ad4cc3ff48d4060e90f8ea498ce987Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor file name it-tidalwave-bluemarine2-downloader High Vendor jar package name it Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor pom name blueMarine II :: Downloader High Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor jar package name downloader Highest Vendor pom artifactid it-tidalwave-bluemarine2-downloader Low Vendor pom parent-artifactid bluemarine2-modules Low Product pom groupid it.tidalwave.bluemarine2 Highest Product file name it-tidalwave-bluemarine2-downloader High Product jar package name it Highest Product Manifest Implementation-Title blueMarine II :: Downloader High Product Manifest specification-title blueMarine II :: Downloader Medium Product pom parent-artifactid bluemarine2-modules Medium Product pom artifactid it-tidalwave-bluemarine2-downloader Highest Product pom name blueMarine II :: Downloader High Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product jar package name downloader Highest Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-initializer-1.1-ALPHA-1.jarDescription:
A module that is responsible for the initialisation of other modules.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-initializer/1.1-ALPHA-1/it-tidalwave-bluemarine2-initializer-1.1-ALPHA-1.jarMD5: 507575a6f97a88b793558b868079aedaSHA1: 1a349c9692e086aba8efc83eb00c74b80b0b6472SHA256: dbb7de5760622b29d50b6484aae78876e7beea1abb6bece8d161e0d776915236Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor file name it-tidalwave-bluemarine2-initializer High Vendor jar package name initializer Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom name blueMarine II :: Initializer High Vendor pom artifactid it-tidalwave-bluemarine2-initializer Low Vendor pom parent-artifactid bluemarine2-modules Low Product file name it-tidalwave-bluemarine2-initializer High Product jar package name initializer Highest Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product Manifest Implementation-Title blueMarine II :: Initializer High Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product pom name blueMarine II :: Initializer High Product pom artifactid it-tidalwave-bluemarine2-initializer Highest Product Manifest specification-title blueMarine II :: Initializer Medium Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-mediaserver-1.1-ALPHA-1.jarDescription:
The abstract model of the component that exposes media.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-mediaserver/1.1-ALPHA-1/it-tidalwave-bluemarine2-mediaserver-1.1-ALPHA-1.jarMD5: 9224fda114b8492ef7128eb0aea26cafSHA1: 276000785eef568737570095536fd802c7c64d44SHA256: 85081720b19e589dcbdabf54721cb71a92e1971a5196cb9ae3a862360593d3dcReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom name blueMarine II :: Media Server High Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor pom artifactid it-tidalwave-bluemarine2-mediaserver Low Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor file name it-tidalwave-bluemarine2-mediaserver High Vendor pom parent-artifactid bluemarine2-modules Low Vendor jar package name mediaserver Highest Product pom name blueMarine II :: Media Server High Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product Manifest specification-title blueMarine II :: Media Server Medium Product pom artifactid it-tidalwave-bluemarine2-mediaserver Highest Product pom parent-artifactid bluemarine2-modules Medium Product Manifest Implementation-Title blueMarine II :: Media Server High Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product file name it-tidalwave-bluemarine2-mediaserver High Product jar package name mediaserver Highest Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-model-1.1-ALPHA-1.jarDescription:
The core model for the application.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-model/1.1-ALPHA-1/it-tidalwave-bluemarine2-model-1.1-ALPHA-1.jarMD5: b5054e83856058deb7aa52409e9ea67dSHA1: 97bbf8594aabfb7d85aca8daef6f0ccf404d6e8cSHA256: f18ccf14a88ce48db2c5e4fe54fcacbe4ac5c9c975f7c198e2dabe4f455c78faReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom name blueMarine II :: Model High Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name model Highest Vendor jar package name tidalwave Highest Vendor file name it-tidalwave-bluemarine2-model High Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom artifactid it-tidalwave-bluemarine2-model Low Vendor pom parent-artifactid bluemarine2-modules Low Product pom artifactid it-tidalwave-bluemarine2-model Highest Product pom name blueMarine II :: Model High Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product Manifest specification-title blueMarine II :: Model Medium Product jar package name model Highest Product Manifest Implementation-Title blueMarine II :: Model High Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product file name it-tidalwave-bluemarine2-model High Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-persistence-1.1-ALPHA-1.jarDescription:
The implementation of RDF persistence.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-persistence/1.1-ALPHA-1/it-tidalwave-bluemarine2-persistence-1.1-ALPHA-1.jarMD5: 5a44b650d03c8141505c755563ebd6a2SHA1: de11aa5ead48f9e6b8a0ae86372906b3680a5238SHA256: ccd2be9b26d20152a11c87ef7026e726dbef821cf966ddedda6b840ca34caa67Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid it-tidalwave-bluemarine2-persistence Low Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor pom name blueMarine II :: Persistence High Vendor jar package name persistence Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor file name it-tidalwave-bluemarine2-persistence High Vendor pom parent-artifactid bluemarine2-modules Low Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product pom name blueMarine II :: Persistence High Product jar package name persistence Highest Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product file name it-tidalwave-bluemarine2-persistence High Product Manifest specification-title blueMarine II :: Persistence Medium Product pom artifactid it-tidalwave-bluemarine2-persistence Highest Product Manifest Implementation-Title blueMarine II :: Persistence High Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jarDescription:
A module that exposes data by means of REST.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jarMD5: 1ecc18ff747a26594c7b63faab80e473SHA1: a0648a2e469d9446425dcd6e1566711be5aaed0fSHA256: 61262ce895c158d4091080599d738a546e1180a7810a83b3fbc5ad6f44fb0cf4Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name rest Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name tidalwave Highest Vendor file name it-tidalwave-bluemarine2-rest High Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom artifactid it-tidalwave-bluemarine2-rest Low Vendor pom name blueMarine II :: Media Server :: REST High Vendor pom parent-artifactid bluemarine2-modules Low Product pom artifactid it-tidalwave-bluemarine2-rest Highest Product jar package name rest Highest Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product file name it-tidalwave-bluemarine2-rest High Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product Manifest Implementation-Title blueMarine II :: Media Server :: REST High Product pom name blueMarine II :: Media Server :: REST High Product Manifest specification-title blueMarine II :: Media Server :: REST Medium Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: bootstrap.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/bootstrap.min.jsMD5: c5b5b2fa19bd66ff23211d9f844e0131SHA1: 791aa054a026bddc0de92bad6cf7a1c6e73713d5SHA256: 2979f9a6e32fc42c3e7406339ee9fe76b31d1b52059776a02b4a7fa6a4fd280aReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name bootstrap High Product file name bootstrap High Version file version 3.3.6 High
Published Vulnerabilities CVE-2018-14040 suppress
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.0 cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha6:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha5:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions from (including) 4.0.0; versions up to (excluding) 4.1.2 cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha2:*:*:*:*:*:* CVE-2018-14041 suppress
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha6:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha5:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions from (including) 4.0.0; versions up to (excluding) 4.1.2 cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha2:*:*:*:*:*:* CVE-2018-14042 suppress
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.0 cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha6:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha5:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions from (including) 4.0.0; versions up to (excluding) 4.1.2 cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha2:*:*:*:*:*:* CVE-2019-8331 suppress
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions from (including) 4.3.0; versions up to (excluding) 4.3.1 cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:redhat:virtualization_manager:4.3:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.1 cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* versions from (including) 14.0.0; versions up to (excluding) 14.1.2.5 cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 12.1.0; versions up to (excluding) 12.1.5.1 cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* versions from (including) 15.0.0; versions up to (excluding) 15.1.0 cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 13.0.0; versions up to (excluding) 13.1.3.4 it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: handlebars.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/handlebars.min.jsMD5: c29e40d32ace051a672be040fadc6683SHA1: 16cbc4c0a67117a5a3e6cfd78ad457359f82faf8SHA256: acc39238ce470f35443285594efdb5f3df912924d2818e5929f4df6a9eeadb31Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name handlebars High Product file name handlebars High Version file version 4.0.5 High
Published Vulnerabilities A prototype pollution vulnerability in handlebars is exploitable if an attacker can control the template (RETIREJS) suppress
A prototype pollution vulnerability in handlebars is exploitable if an attacker can control the template Unscored:
References:
Disallow calling helperMissing and blockHelperMissing directly (RETIREJS) suppress
Disallow calling helperMissing and blockHelperMissing directly Unscored:
References:
Prototype pollution (RETIREJS) suppress
Prototype pollution Unscored:
References:
it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: jquery.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/jquery.min.jsMD5: 6fc159d00dc3cea4153c038739683f93SHA1: 5d7e5bbfa540f0e53bd599e4305e1a4e815b5dd1SHA256: 8a102873a33f24f7eb22221e6b23c4f718e29f85168ecc769a35bfaed9b12cceReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name jquery High Product file name jquery High Version file version 2.2.0 High
Published Vulnerabilities CVE-2015-9251 suppress
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:oracle:financial_services_asset_liability_management:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:retail_allocation:15.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_invoice_matching:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_operations_monitor:3.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_reconciliation_framework:8.0.5:*:*:*:*:*:*:* cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* versions up to (excluding) 3.0.0 cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:* versions from (including) 4.3.0.1; versions up to (including) 4.3.0.4 cpe:2.3:a:oracle:enterprise_operations_monitor:4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:real-time_scheduler:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:service_bus:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:service_bus:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:business_process_management_suite:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:siebel_ui_framework:18.11:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_reporting_and_analytics:9.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:6.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:* versions from (including) 8.0.2; versions up to (including) 8.0.7 cpe:2.3:a:oracle:retail_workforce_management_software:1.64.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_insights:16.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_reconciliation_framework:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* cpe:2.3:a:oracle:siebel_ui_framework:18.10:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:6.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_profitability_management:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.6 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_sales_audit:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:utilities_mobile_workforce_management:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:6.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:endeca_information_discovery_studio:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:oss_support_tools:19.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_webrtc_session_controller:*:*:*:*:*:*:*:* versions up to (excluding) 7.2 cpe:2.3:a:oracle:business_process_management_suite:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_management:*:*:*:*:*:*:*:* versions from (including) 8.0.2; versions up to (including) 8.0.6 cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_integration_hub:*:*:*:*:*:*:*:* versions from (including) 8.0.5; versions up to (including) 8.0.7 cpe:2.3:a:oracle:primavera_gateway:17.12:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_workforce_management_software:1.60.9:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_converged_application_server:*:*:*:*:*:*:*:* versions up to (excluding) 7.0.0.1 cpe:2.3:a:oracle:primavera_gateway:15.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_services_gatekeeper:*:*:*:*:*:*:*:* versions up to (excluding) 6.1.0.4.0 cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* versions from (including) 17.1; versions up to (including) 17.12 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_sites:11.1.1.8.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_cruise_fleet_management:9.0.11:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* versions from (including) 7.3.3; versions up to (including) 7.3.5 cpe:2.3:a:oracle:primavera_gateway:16.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* versions from (including) 8.0.0; versions up to (including) 8.0.7 cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:* CVE-2019-11358 suppress
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:oracle:financial_services_asset_liability_management:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.1.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* versions up to (excluding) 19.1 cpe:2.3:a:oracle:transportation_management:1.4.3:*:*:*:*:*:*:* cpe:2.3:a:redhat:virtualization_manager:4.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_central_office:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_retail_customer_analytics:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.6 cpe:2.3:a:oracle:healthcare_translational_research:3.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:service_bus:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_insights:16.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.0 cpe:2.3:a:oracle:jdeveloper_and_adf:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:siebel_ui_framework:20.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_application_session_controller:3.8m0:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_service_level_management:13.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.6.0; versions up to (excluding) 8.6.15 cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:real-time_scheduler:*:*:*:*:*:*:*:* versions from (including) 2.3.0.1; versions up to (including) 2.3.0.3 cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_simphony:18.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper_and_adf:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_retail_performance_analytics:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:policy_automation:10.4.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 19.12.0; versions up to (including) 19.12.4 cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:* versions from (including) 5.0.0.0; versions up to (including) 5.6.0.0 cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_foundation:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.8 cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_us_federal_reserve:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:tape_library_acsls:8.5.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_enterprise_financial_performance_analytics:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_ifrs_17_analyzer:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.2.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:* cpe:2.3:a:oracle:service_bus:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_service_level_management:13.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:* cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:* versions from (including) 6.0; versions up to (including) 6.4 cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 7.0; versions up to (excluding) 7.66 cpe:2.3:a:oracle:communications_unified_inventory_management:7.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_de_nederlandsche_bank:8.0.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.0.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:rest_data_services:19c:*:*:*:-:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_profitability_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper_and_adf:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* versions from (including) 8.0.2; versions up to (including) 8.1.0 cpe:2.3:a:oracle:rest_data_services:18c:*:*:*:-:*:*:* cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.5.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:* versions from (including) 12.2.0; versions up to (including) 12.2.15 cpe:2.3:a:oracle:communications_analytics:12.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:policy_automation:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* versions from (including) 7.3.3; versions up to (including) 7.3.5 cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 17.12.0; versions up to (including) 17.12.7 cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:* versions from (including) 19.1.0; versions up to (including) 19.1.2 cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* versions from (including) 12.2.0; versions up to (including) 12.2.15 cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_simphony:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:* versions from (including) 2.7.0; versions up to (including) 2.8.0 cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:tape_library_acsls:8.5:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* cpe:2.3:a:oracle:utilities_mobile_workforce_management:*:*:*:*:*:*:*:* versions from (including) 2.3.0.1; versions up to (including) 2.3.0.3 cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 18.8.0; versions up to (including) 18.8.9 cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_retail_performance_analytics:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_ifrs_17_analyzer:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:*:*:*:*:*:*:*:* versions from (including) 4.1; versions up to (including) 4.3 cpe:2.3:a:oracle:financial_services_data_integration_hub:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_performance_insight:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_point-of-service:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:4.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:* cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* versions from (including) 1.11.0; versions up to (excluding) 1.11.9 cpe:2.3:a:oracle:bi_publisher:5.5.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:service_bus:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_session_border_controller:8.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.4.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:* versions from (including) 8.0.2; versions up to (including) 8.0.7 cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:system_utilities:19.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_governance_for_us_regulatory_reporting:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.9 cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* versions from (including) 1.12.0; versions up to (excluding) 1.12.6 cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:siebel_mobile_applications:*:*:*:*:*:*:*:* versions up to (including) 19.8 cpe:2.3:a:oracle:policy_automation:12.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:15.2.18:*:*:*:*:*:*:* cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_integration_hub:*:*:*:*:*:*:*:* versions from (including) 8.0.5; versions up to (including) 8.0.7 cpe:2.3:a:oracle:insurance_accounting_analyzer:8.0.9:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_data_foundation:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* versions from (including) 3.0; versions up to (including) 3.1.3 cpe:2.3:a:oracle:big_data_discovery:1.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_asset_liability_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_profitability_management:*:*:*:*:*:*:*:* versions from (including) 8.0.4; versions up to (including) 8.0.7 cpe:2.3:a:oracle:application_testing_suite:13.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* versions from (including) 17.7; versions up to (including) 17.12 cpe:2.3:a:oracle:diagnostic_assistant:2.12.36:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* versions from (including) 2.4.0; versions up to (including) 2.10.0 cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 16.2.0; versions up to (including) 16.2.11 cpe:2.3:a:oracle:knowledge:*:*:*:*:*:*:*:* versions from (including) 8.6.0; versions up to (including) 8.6.3 cpe:2.3:a:oracle:financial_services_enterprise_financial_performance_analytics:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.5.0; versions up to (excluding) 8.5.15 CVE-2020-11022 suppress
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.8 cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:* versions from (including) 19.1.0; versions up to (including) 19.1.2 cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.7.0; versions up to (excluding) 8.7.14 cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_simphony:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_supplier_collaboration_for_process:6.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_diameter_signaling_router_idih\::*:*:*:*:*:*:*:* versions from (including) 8.0.0; versions up to (including) 8.2.2 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.8 cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_foundation:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.1.0 cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:siebel_ui_framework:20.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_application_session_controller:3.8m0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.8 cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:hospitality_simphony:18.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_integration_hub:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 7.0; versions up to (excluding) 7.70 cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:* versions from (including) 5.0.0.0; versions up to (including) 5.6.0.0 cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.8.0; versions up to (excluding) 8.8.6 cpe:2.3:a:oracle:insurance_data_foundation:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.1.0 cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* versions from (including) 12.2.0; versions up to (including) 12.2.20 cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.8 cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.2.1:*:*:*:*:*:*:* cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* versions from (including) 1.2; versions up to (excluding) 3.5.0 cpe:2.3:a:oracle:enterprise_session_border_controller:8.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:* versions from (including) 12.2.0; versions up to (including) 12.2.20 cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_us_federal_reserve:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.9 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_foundation:7.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_data_governance_for_us_regulatory_reporting:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.9 cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_profitability_management:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.0.8 cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* versions from (including) 8.0.6.0.0; versions up to (including) 8.1.0.0.0 cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.0.8:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_profitability_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_accounting_analyzer:8.0.9:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* versions from (including) 3.0; versions up to (including) 3.1.3 cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_asset_liability_management:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.6:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:*:*:*:*:*:*:*:* versions from (including) 8.0.6; versions up to (including) 8.1.0 cpe:2.3:a:oracle:financial_services_profitability_management:8.0.6:*:*:*:*:*:*:* CVE-2020-11023 suppress
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 17.12.0; versions up to (including) 17.12.7 cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.1:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.7.0; versions up to (excluding) 8.7.14 cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* versions up to (excluding) 9.2.5.0 cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:* versions from (including) 6.1; versions up to (including) 6.4 cpe:2.3:a:netapp:snapcenter_server:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* versions up to (excluding) 20.2 cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_de_nederlandsche_bank:8.0.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.3.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_resources:9.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:* versions from (including) 2.7.0; versions up to (including) 2.8.0 cpe:2.3:a:oracle:rest_data_services:19c:*:*:*:-:*:*:* cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* versions up to (excluding) 9.2.5.0 cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 18.8.0; versions up to (including) 18.8.9 cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:healthcare_translational_research:3.3.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 16.2; versions up to (including) 16.2.11 cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:rest_data_services:18c:*:*:*:-:*:*:* cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* versions from (including) 3.0; versions up to (including) 3.1.3 cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_operations_monitor:*:*:*:*:*:*:*:* versions from (including) 4.1; versions up to (including) 4.3 cpe:2.3:a:oracle:siebel_mobile:*:*:*:*:*:*:*:* versions up to (including) 20.12 cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* versions from (including) 1.0.3; versions up to (excluding) 3.5.0 cpe:2.3:a:oracle:communications_analytics:12.1.1:*:*:*:*:*:*:* cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 7.0; versions up to (excluding) 7.70 cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* versions from (including) 19.12.0; versions up to (including) 19.12.4 cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.8.0; versions up to (excluding) 8.8.6 cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* versions from (including) 2.4.0; versions up to (including) 2.10.0 cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:* it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: luga.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/luga.min.jsMD5: 861cc0e3567b51af13c746cbdf30947eSHA1: 350221d635df64742820f06845b6e6c89b2b3b7dSHA256: 220a496b817fd625011e9fe49c7ae0165b420f96637b74df09957e840a4a2b64Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence
it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: moment.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/moment.min.jsMD5: 0a8c0ed69de37d65b29e9e0de39e1eaaSHA1: 0eeec1bc6e620cd1020bb1a7d5760ed45c969937SHA256: 1a7ecc510a27a3c2d4c537d1034599cc9813b9ae7651d9b521fae4e78db5ce40Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence
it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar: numeral.min.jsFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-rest/1.1-ALPHA-1/it-tidalwave-bluemarine2-rest-1.1-ALPHA-1.jar/webapp/js/numeral.min.jsMD5: 769d83d47eeb4951f02c8848195b9553SHA1: ad79f25aa5ca283d2ec9328008cafaa11f209994SHA256: 01b2c1b9ab356e9899c8e4e72bf4617a7c998d13e2818a7ff4ca9ac3dee80325Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence
it-tidalwave-bluemarine2-services-stoppingdown-1.1-ALPHA-1.jarDescription:
A module that interfaces with StoppingDown website.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-services-stoppingdown/1.1-ALPHA-1/it-tidalwave-bluemarine2-services-stoppingdown-1.1-ALPHA-1.jarMD5: f10113f842fcabc25a81d61d8233fa9eSHA1: bb30d5f9c9611050e34aba71768611ae6e512e02SHA256: a6832e38636b2cbe38385e400fdb88cc2e4bde9185f60e1d5013edba62efdc51Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name tidalwave Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor file name it-tidalwave-bluemarine2-services-stoppingdown High Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom name blueMarine II :: Services :: StoppingDown High Vendor pom parent-artifactid bluemarine2-services-modules Low Vendor pom artifactid it-tidalwave-bluemarine2-services-stoppingdown Low Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Product Manifest specification-title blueMarine II :: Services :: StoppingDown Medium Product jar package name tidalwave Highest Product file name it-tidalwave-bluemarine2-services-stoppingdown High Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product pom parent-artifactid bluemarine2-services-modules Medium Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product pom name blueMarine II :: Services :: StoppingDown High Product pom artifactid it-tidalwave-bluemarine2-services-stoppingdown Highest Product Manifest Implementation-Title blueMarine II :: Services :: StoppingDown High Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-upnp-mediaserver-1.1-ALPHA-1.jarDescription:
This module exposes the media server by means of the UPnP protocol.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-upnp-mediaserver/1.1-ALPHA-1/it-tidalwave-bluemarine2-upnp-mediaserver-1.1-ALPHA-1.jarMD5: 8368f42bd5ad1fbd16defc282f3d51fcSHA1: 6ded8cb14cbca3223dd0932d8e79498006cb0ab9SHA256: 85d0560e38337f111346f401cedf726605d49a9730190b14a293a1cc9c56f164Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom artifactid it-tidalwave-bluemarine2-upnp-mediaserver Low Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor jar package name it Highest Vendor file name it-tidalwave-bluemarine2-upnp-mediaserver High Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor pom name blueMarine II :: Media Server :: UPnP High Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor jar package name upnp Highest Vendor pom parent-artifactid bluemarine2-modules Low Product pom groupid it.tidalwave.bluemarine2 Highest Product jar package name it Highest Product file name it-tidalwave-bluemarine2-upnp-mediaserver High Product Manifest specification-title blueMarine II :: Media Server :: UPnP Medium Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product Manifest Implementation-Title blueMarine II :: Media Server :: UPnP High Product pom name blueMarine II :: Media Server :: UPnP High Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product jar package name upnp Highest Product pom artifactid it-tidalwave-bluemarine2-upnp-mediaserver Highest Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-bluemarine2-vocabulary-1.1-ALPHA-1.jarDescription:
A collection of semantic elements for the database.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/bluemarine2/it-tidalwave-bluemarine2-vocabulary/1.1-ALPHA-1/it-tidalwave-bluemarine2-vocabulary-1.1-ALPHA-1.jarMD5: 6687e82a11c5d2debbb78283341d13b1SHA1: 9c428ccc2eb12149d6984f656d7526c59da5e8d2SHA256: 04deb665a70841f40ac7e5f4b1d43fb3a664315159ac9d13dc56dd690b546317Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom artifactid it-tidalwave-bluemarine2-vocabulary Low Vendor jar package name tidalwave Highest Vendor pom groupid it.tidalwave.bluemarine2 Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor pom name blueMarine II :: Vocabulary High Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor jar package name bluemarine2 Highest Vendor pom parent-artifactid bluemarine2-modules Low Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor file name it-tidalwave-bluemarine2-vocabulary High Product pom parent-artifactid bluemarine2-modules Medium Product jar package name tidalwave Highest Product pom groupid it.tidalwave.bluemarine2 Highest Product Manifest specification-title blueMarine II :: Vocabulary Medium Product pom name blueMarine II :: Vocabulary High Product jar package name it Highest Product Manifest build-jdk-spec 11 Low Product jar package name bluemarine2 Highest Product pom artifactid it-tidalwave-bluemarine2-vocabulary Highest Product Manifest Implementation-Title blueMarine II :: Vocabulary High Product file name it-tidalwave-bluemarine2-vocabulary High Version pom version 1.1-ALPHA-1 Highest
it-tidalwave-messagebus-3.2-ALPHA-11.jarDescription:
An abstract description of a simple message bus to be used within an application.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/thesefoolishthings/it-tidalwave-messagebus/3.2-ALPHA-11/it-tidalwave-messagebus-3.2-ALPHA-11.jarMD5: 5e429b1fdc1357593bdbe4ae2e43eb73SHA1: 6359be911f918b89a7f164e11c91a953a29d7072SHA256: d9d982eea5a0bbdb8769ad675866b3324e544eeeba7a3b1a241bffdf557c5cf0Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid modules Low Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor pom artifactid it-tidalwave-messagebus Low Vendor Manifest build-jdk-spec 11 Low Vendor jar package name messagebus Highest Vendor pom groupid it.tidalwave.thesefoolishthings Highest Vendor file name it-tidalwave-messagebus High Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor pom name TheseFoolishThings :: MessageBus High Product jar package name tidalwave Highest Product Manifest specification-title TheseFoolishThings :: MessageBus Medium Product jar package name it Highest Product Manifest build-jdk-spec 11 Low Product jar package name messagebus Highest Product pom groupid it.tidalwave.thesefoolishthings Highest Product file name it-tidalwave-messagebus High Product Manifest Implementation-Title TheseFoolishThings :: MessageBus High Product pom parent-artifactid modules Medium Product pom artifactid it-tidalwave-messagebus Highest Product pom name TheseFoolishThings :: MessageBus High Version pom version 3.2-ALPHA-11 Highest
it-tidalwave-messagebus-spring-3.2-ALPHA-11.jarDescription:
A Spring implementation of a simple message bus to be used within an application.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/thesefoolishthings/it-tidalwave-messagebus-spring/3.2-ALPHA-11/it-tidalwave-messagebus-spring-3.2-ALPHA-11.jarMD5: 834a621cb0ac1cc5ee479dbf63631627SHA1: 7bdeee0717482d985703c445d3eeed39914db684SHA256: 8ad4ec01a28fd88643e030c44f750c4856070c374e875d1d6ea592e29f03ca02Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid modules Low Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor pom name TheseFoolishThings :: MessageBus :: Spring High Vendor Manifest build-jdk-spec 11 Low Vendor jar package name messagebus Highest Vendor pom groupid it.tidalwave.thesefoolishthings Highest Vendor pom artifactid it-tidalwave-messagebus-spring Low Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor file name it-tidalwave-messagebus-spring High Product pom artifactid it-tidalwave-messagebus-spring Highest Product jar package name tidalwave Highest Product jar package name it Highest Product pom name TheseFoolishThings :: MessageBus :: Spring High Product Manifest build-jdk-spec 11 Low Product jar package name messagebus Highest Product Manifest Implementation-Title TheseFoolishThings :: MessageBus :: Spring High Product pom groupid it.tidalwave.thesefoolishthings Highest Product pom parent-artifactid modules Medium Product file name it-tidalwave-messagebus-spring High Product Manifest specification-title TheseFoolishThings :: MessageBus :: Spring Medium Version pom version 3.2-ALPHA-11 Highest
it-tidalwave-role-3.2-ALPHA-11.jarDescription:
Roles are a powerful way for designing complex behaviours while keeping good practices such as Single Responsibility, Dependency Inversion and
Interface Segregation.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/thesefoolishthings/it-tidalwave-role/3.2-ALPHA-11/it-tidalwave-role-3.2-ALPHA-11.jarMD5: 80ba630d9714bee82e8ec9e143a4b3c9SHA1: 1ca57201c455a955a9995ab1d48289fed76d8800SHA256: 7e847b7a3d662155d47077626d315bd75d42f28300b22db54d7cfb9fed031d0aReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid modules Low Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor pom name TheseFoolishThings :: Roles High Vendor pom groupid it.tidalwave.thesefoolishthings Highest Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor file name it-tidalwave-role High Vendor pom artifactid it-tidalwave-role Low Vendor jar package name role Highest Product Manifest specification-title TheseFoolishThings :: Roles Medium Product pom artifactid it-tidalwave-role Highest Product jar package name tidalwave Highest Product jar package name it Highest Product Manifest build-jdk-spec 11 Low Product pom name TheseFoolishThings :: Roles High Product pom groupid it.tidalwave.thesefoolishthings Highest Product Manifest Implementation-Title TheseFoolishThings :: Roles High Product pom parent-artifactid modules Medium Product file name it-tidalwave-role High Product jar package name role Highest Version pom version 3.2-ALPHA-11 Highest
it-tidalwave-role-spring-3.2-ALPHA-11.jarDescription:
Specific Spring support for DCI roles.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/thesefoolishthings/it-tidalwave-role-spring/3.2-ALPHA-11/it-tidalwave-role-spring-3.2-ALPHA-11.jarMD5: ac8fa9eba8d4662b7087daa65f0ccb06SHA1: efbb2304fffe6760b83a31e2e5fcecf9512406b3SHA256: 105ec6e5a8ec86429c3b4768f01814dca461dd133e6d37e3c96acd9aa8b06c2eReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name spring Highest Vendor jar package name it Highest Vendor pom artifactid it-tidalwave-role-spring Low Vendor pom name TheseFoolishThings :: Roles :: Spring High Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Vendor pom parent-artifactid modules Low Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor Manifest build-jdk-spec 11 Low Vendor pom groupid it.tidalwave.thesefoolishthings Highest Vendor file name it-tidalwave-role-spring High Vendor jar package name role Highest Product jar package name spring Highest Product Manifest specification-title TheseFoolishThings :: Roles :: Spring Medium Product jar package name it Highest Product pom artifactid it-tidalwave-role-spring Highest Product pom parent-artifactid modules Medium Product pom name TheseFoolishThings :: Roles :: Spring High Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product pom groupid it.tidalwave.thesefoolishthings Highest Product file name it-tidalwave-role-spring High Product Manifest Implementation-Title TheseFoolishThings :: Roles :: Spring High Product jar package name role Highest Version pom version 3.2-ALPHA-11 Highest
it-tidalwave-role-ui-javafx-1.1-ALPHA-2.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/steelblue/it-tidalwave-role-ui-javafx/1.1-ALPHA-2/it-tidalwave-role-ui-javafx-1.1-ALPHA-2.jarMD5: 04595283cb55863ac87a817253ca60aeSHA1: e189745e52eac13dc6000594214142da2d64ffb8SHA256: a09c323a23445fff711856d3389ce841a0a52c3bed83c2c00fc37d5ebe567befReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor Tidalwave s.a.s. (http://tidalwave.it) High Vendor pom artifactid it-tidalwave-role-ui-javafx Low Vendor jar package name it Highest Vendor jar package name javafx Highest Vendor pom name SteelBlue - JavaFX Bindings High Vendor jar package name tidalwave Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest specification-vendor Tidalwave s.a.s. (http://tidalwave.it) Low Vendor file name it-tidalwave-role-ui-javafx High Vendor jar package name ui Highest Vendor pom groupid it.tidalwave.steelblue Highest Vendor jar package name role Highest Vendor pom parent-artifactid it-tidalwave-steelblue-modules Low Product jar package name it Highest Product jar package name javafx Highest Product Manifest specification-title SteelBlue - JavaFX Bindings Medium Product Manifest Implementation-Title SteelBlue - JavaFX Bindings High Product pom artifactid it-tidalwave-role-ui-javafx Highest Product pom name SteelBlue - JavaFX Bindings High Product jar package name tidalwave Highest Product Manifest build-jdk-spec 11 Low Product file name it-tidalwave-role-ui-javafx High Product jar package name ui Highest Product pom parent-artifactid it-tidalwave-steelblue-modules Medium Product pom groupid it.tidalwave.steelblue Highest Product jar package name role Highest Version pom version 1.1-ALPHA-2 Highest
it-tidalwave-util-3.2-ALPHA-11.jarDescription:
A collection of common utilities.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/it/tidalwave/thesefoolishthings/it-tidalwave-util/3.2-ALPHA-11/it-tidalwave-util-3.2-ALPHA-11.jarMD5: 177cfe76d9466ac36a64135f63fb3b11SHA1: 1a9d9cd4f18be3e11f7b6a43b767f5d3a0f5dbdeSHA256: c2a653eccad40eef79de288779dc5e30999b15e2d68d561b82c7e8bf9356aeabReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid it-tidalwave-util Low Vendor jar package name util Highest Vendor pom parent-artifactid modules Low Vendor jar package name tidalwave Highest Vendor Manifest specification-vendor Tidalwave s.a.s. Low Vendor jar package name it Highest Vendor Manifest build-jdk-spec 11 Low Vendor pom name TheseFoolishThings :: Utilities High Vendor pom groupid it.tidalwave.thesefoolishthings Highest Vendor file name it-tidalwave-util High Vendor Manifest Implementation-Vendor Tidalwave s.a.s. High Product Manifest specification-title TheseFoolishThings :: Utilities Medium Product jar package name util Highest Product jar package name tidalwave Highest Product jar package name it Highest Product pom artifactid it-tidalwave-util Highest Product Manifest build-jdk-spec 11 Low Product pom name TheseFoolishThings :: Utilities High Product pom groupid it.tidalwave.thesefoolishthings Highest Product file name it-tidalwave-util High Product pom parent-artifactid modules Medium Product Manifest Implementation-Title TheseFoolishThings :: Utilities High Version pom version 3.2-ALPHA-11 Highest
jackson-core-2.12.2.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/fasterxml/jackson/core/jackson-core/2.12.2/jackson-core-2.12.2.jar
MD5: d9c1faa07f50abade5c796de00c4b23c
SHA1: 8df50138521d05561a308ec2799cc8dda20c06df
SHA256: 7883331763729b72735fdd8a117f32eb7d22695babfb37cc99df8392c196efc3
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jackson-core Low Vendor pom url FasterXML/jackson-core Highest Vendor jar package name fasterxml Highest Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom groupid fasterxml.jackson.core Highest Vendor jar package name json Highest Vendor file name jackson-core High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest Implementation-Vendor FasterXML High Vendor jar package name jackson Highest Vendor pom parent-artifactid jackson-base Low Vendor Manifest implementation-build-date 2021-03-03 20:55:33+0000 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor jar package name base Highest Vendor Manifest specification-vendor FasterXML Low Vendor pom name Jackson-core High Vendor jar package name core Highest Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Product pom url FasterXML/jackson-core High Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest build-jdk-spec 1.8 Low Product pom parent-groupid com.fasterxml.jackson Medium Product hint analyzer product modules Highest Product jar package name json Highest Product jar package name version Highest Product Manifest Bundle-Name Jackson-core Medium Product jar package name jackson Highest Product Manifest Implementation-Title Jackson-core High Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product jar package name base Highest Product pom name Jackson-core High Product hint analyzer product java8 Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product Manifest specification-title Jackson-core Medium Product pom groupid fasterxml.jackson.core Highest Product file name jackson-core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest implementation-build-date 2021-03-03 20:55:33+0000 Low Product pom parent-artifactid jackson-base Medium Product pom artifactid jackson-core Highest Version Manifest Bundle-Version 2.12.2 High Version pom version 2.12.2 Highest Version Manifest Implementation-Version 2.12.2 High Version file version 2.12.2 High
Related Dependencies jackson-annotations-2.12.2.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/fasterxml/jackson/core/jackson-annotations/2.12.2/jackson-annotations-2.12.2.jar MD5: 000332535aef84b64b67a549a9d0d40d SHA1: 0a770cc4c0a1fb0bfd8a150a6a0004e42bc99fca SHA256: 558561786c071af202e849b6ae3d39c87ed417ecc83d45e398c12eb3bffa557b pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.12.2 jackson-datatype-jdk8-2.12.2.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.12.2/jackson-datatype-jdk8-2.12.2.jar MD5: 4bd75a5160ff4c7696009e666e311111 SHA1: 7758f026658b2b9c43bdc5c25d72faa22379c892 SHA256: ebd595dd8913c3996096bf03a93873baedd8862f0596db33cbe6d0955e334995 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.12.2 jackson-databind-2.12.2.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/fasterxml/jackson/core/jackson-databind/2.12.2/jackson-databind-2.12.2.jar
MD5: 8ce740ce76d0b2b0f6e4a13f4dc58c4f
SHA1: 5f9d79e09ebf5d54a46e9f4543924cf7ae7654e0
SHA256: c4002f861d8d33f3202bf8effabb53acc320c5276cc50c1bfaae73c36ce8db32
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name fasterxml Highest Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom groupid fasterxml.jackson.core Highest Vendor file name jackson-databind High Vendor Manifest Implementation-Vendor FasterXML High Vendor jar package name jackson Highest Vendor jar package name databind Highest Vendor pom artifactid jackson-databind Low Vendor pom parent-artifactid jackson-base Low Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest implementation-build-date 2021-03-03 21:21:04+0000 Low Vendor Manifest specification-vendor FasterXML Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor pom name jackson-databind High Vendor pom url http://github.com/FasterXML/jackson Highest Product Manifest Implementation-Title jackson-databind High Product jar package name fasterxml Highest Product Manifest build-jdk-spec 1.8 Low Product pom parent-groupid com.fasterxml.jackson Medium Product hint analyzer product modules Highest Product pom groupid fasterxml.jackson.core Highest Product file name jackson-databind High Product Manifest Bundle-Name jackson-databind Medium Product jar package name jackson Highest Product jar package name databind Highest Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom parent-artifactid jackson-base Medium Product pom artifactid jackson-databind Highest Product Manifest implementation-build-date 2021-03-03 21:21:04+0000 Low Product Manifest specification-title jackson-databind Medium Product pom url http://github.com/FasterXML/jackson Medium Product hint analyzer product java8 Highest Product pom name jackson-databind High Version Manifest Bundle-Version 2.12.2 High Version pom version 2.12.2 Highest Version Manifest Implementation-Version 2.12.2 High Version file version 2.12.2 High
jaudiotagger-2.2.5.jarDescription:
The aim of this project is to provide a world class Java library
for editing tag information in audio files.
Most existing solutions are not java based inhibiting the use of
java applications with digital files.
License:
LGPL: http://www.gnu.org/copyleft/lesser.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/net/jthink/jaudiotagger/2.2.5/jaudiotagger-2.2.5.jar
MD5: 192fd43df458a04d32b215e38489f8ae
SHA1: e9a1c27942a89439e3f8dca737075b7a354a46e1
SHA256: ccf8dc43a2846de375c97e834114b904febc3f4792e103692149a2498d5e390d
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name tag Low Vendor pom url https://bitbucket.org/ijabz/jaudiotagger Highest Vendor file name jaudiotagger High Vendor pom artifactid jaudiotagger Low Vendor jar package name jaudiotagger Low Vendor jar package name tag Highest Vendor pom name jaudiotagger High Vendor pom groupid net.jthink Highest Vendor jar package name audio Highest Vendor jar package name jaudiotagger Highest Vendor pom parent-groupid net.java Medium Vendor pom organization name jthink.net High Vendor pom parent-artifactid jvnet-parent Low Vendor pom organization url http://jthink.net/ Medium Product jar package name tag Low Product pom organization name jthink.net Low Product file name jaudiotagger High Product pom organization url http://jthink.net/ Low Product jar package name tag Highest Product pom parent-artifactid jvnet-parent Medium Product pom name jaudiotagger High Product pom groupid net.jthink Highest Product jar package name audio Highest Product pom artifactid jaudiotagger Highest Product jar package name jaudiotagger Highest Product pom parent-groupid net.java Medium Product pom url https://bitbucket.org/ijabz/jaudiotagger Medium Version file version 2.2.5 High Version pom parent-version 2.2.5 Low Version pom version 2.2.5 Highest
javafx-base-11.0.1-mac.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-base/11.0.1/javafx-base-11.0.1-mac.jarMD5: 94933060e439fba99478e14fcf2d1b02SHA1: 2b9ca67aea06b0ea7aa0e740498fc97c822b307eSHA256: 2d8052a08fd2e5d98e1d5a16d724ea5dd02102879de20a193225f57199803983Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name beans Low Vendor pom groupid org.openjfx Highest Vendor file name javafx-base High Vendor jar package name javafx Low Product pom artifactid javafx-base Highest Product jar package name beans Low Product file name javafx-base High Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-base-11.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-base/11.0.1/javafx-base-11.0.1.jarMD5: b85ce0631dae83fe643fbd32ccd08e4cSHA1: f1354a284f4151d20358e776f6ff68ee35bbb96dSHA256: c5084a74417a89c69a0c122fae96a4b70bf619fc3d6218ea102a4047ec85ad04Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name javafx.baseEmpty Medium Vendor pom parent-artifactid javafx Low Vendor pom parent-groupid org.openjfx Medium Vendor pom artifactid javafx-base Low Vendor pom groupid openjfx Highest Vendor pom groupid org.openjfx Highest Vendor file name javafx-base High Product Manifest automatic-module-name javafx.baseEmpty Medium Product pom artifactid javafx-base Highest Product pom parent-groupid org.openjfx Medium Product pom parent-artifactid javafx Medium Product pom groupid openjfx Highest Product file name javafx-base High Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-controls-11.0.1-mac.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-controls/11.0.1/javafx-controls-11.0.1-mac.jarMD5: f321c782b9bf158a630cb0a7bea73644SHA1: 0538fd08a4ecd76788766a69c19e90b4cc0179f8SHA256: 148468742e957b765d5ac6d5ba66ce983e1acdf582c191bb35dbfe8cdefdb314Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name scene Low Vendor jar package name control Low Vendor file name javafx-controls High Vendor pom groupid org.openjfx Highest Vendor jar package name javafx Low Product jar package name scene Low Product jar package name control Low Product pom artifactid javafx-controls Highest Product file name javafx-controls High Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-controls-11.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-controls/11.0.1/javafx-controls-11.0.1.jarMD5: 2e18fc95e4aa7ce325cefa67b9f61f3dSHA1: 61cf91bf3494d0616216f49c9e1d183d170adf0aSHA256: 71be28dc4d80744ba541fc50d933729e8703fe1e642ae92037f6fccc7f961971Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid javafx-controls Low Vendor Manifest automatic-module-name javafx.controlsEmpty Medium Vendor pom parent-artifactid javafx Low Vendor pom parent-groupid org.openjfx Medium Vendor file name javafx-controls High Vendor pom groupid openjfx Highest Vendor pom groupid org.openjfx Highest Product Manifest automatic-module-name javafx.controlsEmpty Medium Product pom parent-groupid org.openjfx Medium Product pom artifactid javafx-controls Highest Product pom parent-artifactid javafx Medium Product file name javafx-controls High Product pom groupid openjfx Highest Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-fxml-11.0.1-mac.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-fxml/11.0.1/javafx-fxml-11.0.1-mac.jarMD5: a835057792b4fc1aa7d6c4bea9547addSHA1: 352a51a0f0cb13cf83a081b5dd5526acd4fbab30SHA256: 56f9a32b3a1fc76c761bd40c16917ed1675c8d5dcbe492a44ce9ee2391e27139Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor file name javafx-fxml High Vendor jar package name fxml Low Vendor pom groupid org.openjfx Highest Vendor jar package name javafx Low Product file name javafx-fxml High Product pom artifactid javafx-fxml Highest Product jar package name fxml Low Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-fxml-11.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-fxml/11.0.1/javafx-fxml-11.0.1.jarMD5: 6e4c64769d877a47edbdd0023d89a074SHA1: f290c13d7e984d880c9f114f38c2da949ef18d54SHA256: 546fc449f01cd0bbe51a921f9d3f0e5d8764764480caca4a709e681e7ad0b6cfReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor file name javafx-fxml High Vendor pom parent-artifactid javafx Low Vendor pom parent-groupid org.openjfx Medium Vendor pom artifactid javafx-fxml Low Vendor Manifest automatic-module-name javafx.fxmlEmpty Medium Vendor pom groupid openjfx Highest Vendor pom groupid org.openjfx Highest Product file name javafx-fxml High Product pom artifactid javafx-fxml Highest Product pom parent-groupid org.openjfx Medium Product pom parent-artifactid javafx Medium Product Manifest automatic-module-name javafx.fxmlEmpty Medium Product pom groupid openjfx Highest Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-graphics-11.0.1-mac.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-graphics/11.0.1/javafx-graphics-11.0.1-mac.jarMD5: 64a05ff45e2ff0e9695817816284daf5SHA1: 3c5014c500e6d308eca4ac9f952d4f7e7e8dfc7eSHA256: e0bcd295cae13c636f92911474acbab6bee836e6950d1696a02d79a041d61df2Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor file name javafx-graphics High Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor pom groupid org.openjfx Highest Vendor jar package name javafx Low Product file name javafx-graphics High Product pom artifactid javafx-graphics Highest Version pom version 11.0.1 Highest Version file version 11.0.1 High
javafx-graphics-11.0.1-mac.jar: javafx-swt.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-graphics/11.0.1/javafx-graphics-11.0.1-mac.jar/javafx-swt.jarMD5: ee1545edcd485b34080e9389f2f86b5eSHA1: c12e9a9d5ad723c3e2b60651659b0290d68d9e48SHA256: a7432e9a357e03571ded2ef3d148086b92c297605797bcb31d37eb95b4779317Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name swt Low Vendor jar package name embed Low Vendor file name javafx-swt High Vendor jar package name javafx Low Product jar package name swt Low Product jar package name embed Low Product file name javafx-swt High
javafx-graphics-11.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/openjfx/javafx-graphics/11.0.1/javafx-graphics-11.0.1.jarMD5: ff0579b2b89bfc26f6eb73f812076a1bSHA1: e062cb01783effc6413abbd94d1838f6b0add209SHA256: f597c672a4337a75ba856f38cf548c524b039f452423c34b55653e56c306733dReferenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor file name javafx-graphics High Vendor pom parent-artifactid javafx Low Vendor pom parent-groupid org.openjfx Medium Vendor Manifest automatic-module-name javafx.graphicsEmpty Medium Vendor pom groupid openjfx Highest Vendor pom artifactid javafx-graphics Low Vendor pom groupid org.openjfx Highest Product file name javafx-graphics High Product pom artifactid javafx-graphics Highest Product pom parent-groupid org.openjfx Medium Product Manifest automatic-module-name javafx.graphicsEmpty Medium Product pom parent-artifactid javafx Medium Product pom groupid openjfx Highest Version pom version 11.0.1 Highest Version file version 11.0.1 High
javax.annotation-api-1.3.2.jarDescription:
Common Annotations for the JavaTM Platform API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.annotation/blob/master/LICENSE File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/javax/annotation/javax.annotation-api/1.3.2/javax.annotation-api-1.3.2.jar
MD5: 2ab1973eefffaa2aeec47d50b9e40b9d
SHA1: 934c04d3cfef185a8008e7bf34331b79730a9d43
SHA256: e04ba5195bcd555dc95650f7cc614d151e4bcd52d29a10b8aa2197f3ab89ab9b
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name annotation Highest Vendor pom artifactid javax.annotation-api Low Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest bundle-docurl https://javaee.github.io/glassfish Low Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom groupid javax.annotation Highest Vendor pom organization name GlassFish Community High Vendor pom name ${extension.name} API High Vendor pom parent-groupid net.java Medium Vendor pom parent-artifactid jvnet-parent Low Vendor file name javax.annotation-api High Vendor Manifest extension-name javax.annotation Medium Vendor pom organization url https://javaee.github.io/glassfish Medium Vendor jar package name javax Highest Vendor Manifest bundle-symbolicname javax.annotation-api Medium Vendor Manifest automatic-module-name java.annotation Medium Product jar package name annotation Highest Product Manifest bundle-docurl https://javaee.github.io/glassfish Low Product pom artifactid javax.annotation-api Highest Product pom groupid javax.annotation Highest Product pom parent-artifactid jvnet-parent Medium Product pom name ${extension.name} API High Product pom url http://jcp.org/en/jsr/detail?id=250 Medium Product pom parent-groupid net.java Medium Product file name javax.annotation-api High Product Manifest extension-name javax.annotation Medium Product jar package name javax Highest Product Manifest bundle-symbolicname javax.annotation-api Medium Product pom organization url https://javaee.github.io/glassfish Low Product Manifest Bundle-Name javax.annotation API Medium Product Manifest automatic-module-name java.annotation Medium Product pom organization name GlassFish Community Low Version file version 1.3.2 High Version pom version 1.3.2 Highest Version pom parent-version 1.3.2 Low Version Manifest Implementation-Version 1.3.2 High Version Manifest Bundle-Version 1.3.2 High
javax.inject-1.jarDescription:
The javax.inject API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid javax.inject Highest Vendor file name javax.inject-1 High Vendor pom name javax.inject High Vendor jar package name javax Highest Vendor jar package name inject Highest Vendor pom artifactid javax.inject Low Vendor pom url http://code.google.com/p/atinject/ Highest Vendor jar package name inject Low Vendor jar package name javax Low Product file name javax.inject-1 High Product pom groupid javax.inject Highest Product pom name javax.inject High Product jar package name javax Highest Product pom url http://code.google.com/p/atinject/ Medium Product jar package name inject Highest Product pom artifactid javax.inject Highest Product jar package name inject Low Version pom version 1 Highest Version file version 1 Medium
jaxb-api-2.2.11.jarDescription:
JAXB (JSR 222) API License:
CDDL 1.1: https://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/javax/xml/bind/jaxb-api/2.2.11/jaxb-api-2.2.11.jar
MD5: 5983d1e2ec1a9b0604575cd9e9582591
SHA1: 32274d4244967ff43e7a5d967743d94ed3d2aea7
SHA256: 273d82f8653b53ad9d00ce2b2febaef357e79a273560e796ff3fcfec765f8910
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name bind Highest Vendor pom artifactid jaxb-api Low Vendor pom url http://jaxb.java.net/ Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor pom name Java Architecture for XML Binding High Vendor jar package name jaxb Highest Vendor jar package name xml Highest Vendor pom parent-groupid net.java Medium Vendor pom parent-artifactid jvnet-parent Low Vendor jar package name javax Highest Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor Manifest implementation-build-id tags/jaxb-api-2.2.11-1631, 2013-09-06T10:10:58+0000 Low Vendor file name jaxb-api High Vendor pom organization name Oracle Corporation High Vendor pom groupid javax.xml.bind Highest Vendor Manifest extension-name javax.xml.bind Medium Vendor pom organization url http://www.oracle.com/ Medium Product jar package name bind Highest Product Manifest Bundle-Name jaxb-api Medium Product Manifest specification-title Java Architecture for XML Binding Medium Product pom parent-artifactid jvnet-parent Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom name Java Architecture for XML Binding High Product pom url http://jaxb.java.net/ Medium Product jar package name jaxb Highest Product jar package name xml Highest Product pom parent-groupid net.java Medium Product pom artifactid jaxb-api Highest Product pom organization name Oracle Corporation Low Product jar package name javax Highest Product Manifest bundle-symbolicname jaxb-api Medium Product Manifest implementation-build-id tags/jaxb-api-2.2.11-1631, 2013-09-06T10:10:58+0000 Low Product file name jaxb-api High Product Manifest extension-name javax.xml.bind Medium Product pom groupid javax.xml.bind Highest Product pom organization url http://www.oracle.com/ Low Version pom parent-version 2.2.11 Low Version Manifest Bundle-Version 2.2.11 High Version Manifest specification-version 2.2.11 High Version pom version 2.2.11 Highest Version file version 2.2.11 High
jaxb-core-2.2.11.jarDescription:
Old JAXB Core module. Contains sources required by XJC, JXC and Runtime modules with dependencies. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar
MD5: c5eca4e58a75eabe3379926803421bab
SHA1: c3f87d654f8d5943cd08592f3f758856544d279a
SHA256: b13da0c655a3d590a2a945553648c407e6347648c9f7a3f811b7b3a8a1974baa
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name bind Highest Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom parent-artifactid jaxb-bundles Low Vendor file name jaxb-core High Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-core Medium Vendor jar package name sun Highest Vendor pom groupid glassfish.jaxb Highest Vendor pom groupid sun.xml.bind Highest Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor jar package name xml Highest Vendor pom name JAXB Core High Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Vendor Manifest Implementation-Vendor Oracle High Vendor pom artifactid jaxb-core Low Vendor pom parent-artifactid jaxb-parent Low Vendor pom name Old JAXB Core High Vendor pom groupid com.sun.xml.bind Highest Product jar package name bind Highest Product pom parent-groupid com.sun.xml.bind.mvn Medium Product file name jaxb-core High Product Manifest Implementation-Title JAXB Implementation High Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-core Medium Product Manifest specification-title Java Architecture for XML Binding Medium Product jar package name sun Highest Product pom groupid glassfish.jaxb Highest Product pom groupid sun.xml.bind Highest Product Manifest Bundle-Name Old JAXB Core Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product jar package name xml Highest Product pom name JAXB Core High Product pom artifactid jaxb-core Highest Product Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Product pom parent-artifactid jaxb-parent Medium Product pom name Old JAXB Core High Product pom parent-artifactid jaxb-bundles Medium Version Manifest build-id 2.2.11 Medium Version Manifest Bundle-Version 2.2.11 High Version Manifest Implementation-Version 2.2.11 High Version Manifest major-version 2.2.11 Medium Version pom version 2.2.11 Highest Version file version 2.2.11 High
jaxb-core-2.2.11.jar (shaded: com.sun.istack:istack-commons-runtime:2.21)File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar/META-INF/maven/com.sun.istack/istack-commons-runtime/pom.xmlMD5: caebf95d1d57fc0321b36137e246e192SHA1: 04c234cf684a202c5c9bb7f0a198ba97e958f8f4SHA256: ebe7137b5fbfd050545f9a7f3f339ae55beb0b53755071b4fd62aa024c626d1cReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom groupid sun.istack Highest Vendor pom parent-groupid com.sun.istack Medium Vendor pom parent-artifactid istack-commons Low Vendor pom name istack common utility code runtime High Vendor pom artifactid istack-commons-runtime Low Product pom parent-artifactid istack-commons Medium Product pom groupid sun.istack Highest Product pom artifactid istack-commons-runtime Highest Product pom parent-groupid com.sun.istack Medium Product pom name istack common utility code runtime High Version pom version 2.21 Highest
jaxb-core-2.2.11.jar (shaded: org.glassfish.jaxb:txw2:2.2.11)Description:
TXW is a library that allows you to write XML documents.
File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/sun/xml/bind/jaxb-core/2.2.11/jaxb-core-2.2.11.jar/META-INF/maven/org.glassfish.jaxb/txw2/pom.xmlMD5: 83d24d59202baf2810daa01739963822SHA1: 4be03527dbf2428f7ea99fb9c2f50f089dffad5eSHA256: 8514cb724b4fca59a5cf272b632e539bd0a0f3cacf1844082d0a173a86406bd8Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom artifactid txw2 Low Vendor pom groupid glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom artifactid txw2 Highest Product pom groupid glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Version pom version 2.2.11 Highest
jaxb-impl-2.2.11.jarDescription:
Old JAXB Runtime module. Contains sources required for runtime processing. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/sun/xml/bind/jaxb-impl/2.2.11/jaxb-impl-2.2.11.jar
MD5: bea06b3ee5ef2c338beac9187b7782f3
SHA1: a49ce57aee680f9435f49ba6ef427d38c93247a6
SHA256: f91793a96f185a2fc004c86a37086f060985854ce6b19935e03c4de51e3201d2
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name bind Highest Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom parent-artifactid jaxb-bundles Low Vendor Manifest originally-created-by Apache Maven 3.0.4 Low Vendor jar (hint) package name oracle Highest Vendor jar package name sun Highest Vendor pom groupid sun.xml.bind Highest Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor pom artifactid jaxb-impl Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor jar package name xml Highest Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium Vendor pom name Old JAXB Runtime High Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Vendor Manifest Implementation-Vendor Oracle High Vendor file name jaxb-impl High Vendor pom groupid com.sun.xml.bind Highest Product jar package name bind Highest Product pom parent-groupid com.sun.xml.bind.mvn Medium Product Manifest Bundle-Name Old JAXB Runtime Medium Product pom artifactid jaxb-impl Highest Product Manifest Implementation-Title JAXB Implementation High Product Manifest originally-created-by Apache Maven 3.0.4 Low Product Manifest specification-title Java Architecture for XML Binding Medium Product jar package name sun Highest Product pom groupid sun.xml.bind Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product jar package name xml Highest Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium Product pom name Old JAXB Runtime High Product Manifest git-revision f92ac5110f00752578034111d2f8a10bb0c466e3 Low Product file name jaxb-impl High Product pom parent-artifactid jaxb-bundles Medium Version Manifest build-id 2.2.11 Medium Version Manifest Bundle-Version 2.2.11 High Version Manifest Implementation-Version 2.2.11 High Version Manifest major-version 2.2.11 Medium Version pom version 2.2.11 Highest Version file version 2.2.11 High
jaxb-impl-2.2.11.jar (shaded: org.glassfish.jaxb:jaxb-runtime:2.2.11)Description:
JAXB (JSR 222) Reference Implementation File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/sun/xml/bind/jaxb-impl/2.2.11/jaxb-impl-2.2.11.jar/META-INF/maven/org.glassfish.jaxb/jaxb-runtime/pom.xmlMD5: fa2e4dc2609e6a4d96418f4ac6519e8dSHA1: 6a1651361e4c2392aff30da0df648187f670f8cbSHA256: e5327b31b595ab8143e97836d5ccdf85feb91e7ff5666f7b26913632facca4aaReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom artifactid jaxb-runtime Low Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom groupid glassfish.jaxb Highest Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom parent-artifactid jaxb-runtime-parent Medium Product pom name JAXB Runtime High Product pom groupid glassfish.jaxb Highest Product pom artifactid jaxb-runtime Highest Version pom version 2.2.11 Highest
jcl-over-slf4j-1.7.30.jarDescription:
JCL 1.2 implemented over SLF4J License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/slf4j/jcl-over-slf4j/1.7.30/jcl-over-slf4j-1.7.30.jar
MD5: 69ad224b2feb6f86554fe8997b9c3d4b
SHA1: cd92524ea19d27e5b94ecd251e1af729cffdfe15
SHA256: 71e9ee37b9e4eb7802a2acc5f41728a4cf3915e7483d798db3b4ff2ec8847c50
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom url http://www.slf4j.org Highest Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium Vendor pom name JCL 1.2 implemented over SLF4J High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor file name jcl-over-slf4j High Vendor Manifest automatic-module-name org.apache.commons.logging Medium Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor pom parent-groupid org.slf4j Medium Vendor jar package name apache Highest Vendor pom artifactid jcl-over-slf4j Low Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid slf4j Highest Product Manifest Implementation-Title jcl-over-slf4j High Product Manifest bundle-symbolicname jcl.over.slf4j Medium Product pom name JCL 1.2 implemented over SLF4J High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product file name jcl-over-slf4j High Product Manifest Bundle-Name jcl-over-slf4j Medium Product Manifest automatic-module-name org.apache.commons.logging Medium Product jar package name commons Highest Product jar package name logging Highest Product pom parent-artifactid slf4j-parent Medium Product pom parent-groupid org.slf4j Medium Product jar package name apache Highest Product pom artifactid jcl-over-slf4j Highest Product pom url http://www.slf4j.org Medium Product pom groupid slf4j Highest Version Manifest Implementation-Version 1.7.30 High Version Manifest Bundle-Version 1.7.30 High Version pom version 1.7.30 Highest Version file version 1.7.30 High
jetty-http-10.0.1.jarDescription:
Jetty module for Jetty :: Http Utility License:
https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0 File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-http/10.0.1/jetty-http-10.0.1.jar
MD5: 1ab05e224ff68c7893f434271b340c58
SHA1: bc5fd44f638be64ee6e665e53abb6122c179ccb0
SHA256: 43f3566dc7e8b97b023f5b61b1caca98e54cfcd7cceb93066ae7aa4332b723ec
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name http Highest Vendor pom parent-groupid org.eclipse.jetty Medium Vendor Manifest url https://www.eclipse.org/jetty/ Low Vendor Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.processor)";resolution:=optional,osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)";resolution:=optional,osgi.serviceloader;cardinality:=multiple;filter:="(osgi.serviceloader=org.eclipse.jetty.http.HttpFieldPreEncoder)";resolution:=optional Low Vendor pom groupid eclipse.jetty Highest Vendor Manifest Implementation-Vendor Eclipse Jetty Project High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low Vendor pom parent-artifactid jetty-project Low Vendor file name jetty-http High Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Vendor Manifest bundle-symbolicname org.eclipse.jetty.http Medium Vendor jar package name jetty Highest Vendor pom artifactid jetty-http Low Vendor pom groupid org.eclipse.jetty Highest Vendor pom name Jetty :: Http Utility High Vendor Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Product jar package name http Highest Product pom parent-groupid org.eclipse.jetty Medium Product Manifest url https://www.eclipse.org/jetty/ Low Product Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.processor)";resolution:=optional,osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)";resolution:=optional,osgi.serviceloader;cardinality:=multiple;filter:="(osgi.serviceloader=org.eclipse.jetty.http.HttpFieldPreEncoder)";resolution:=optional Low Product pom groupid eclipse.jetty Highest Product Manifest Bundle-Name Jetty :: Http Utility Medium Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low Product pom parent-artifactid jetty-project Medium Product file name jetty-http High Product jar package name httpfieldpreencoder Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Product Manifest bundle-symbolicname org.eclipse.jetty.http Medium Product jar package name jetty Highest Product pom name Jetty :: Http Utility High Product pom artifactid jetty-http Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Version file version 10.0.1 High Version pom version 10.0.1 Highest Version Manifest Bundle-Version 10.0.1 High Version Manifest Implementation-Version 10.0.1 High
Related Dependencies jetty-util-10.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-util/10.0.1/jetty-util-10.0.1.jar MD5: c05068939f312ef843951017d0bd8d84 SHA1: 0526930825ac759cbc1c622d25d76d996cf88586 SHA256: 177fecaccb422d700fda96cd766dffde9fa9d9ac531dc7076a2d780c379423a2 pkg:maven/org.eclipse.jetty/jetty-util@10.0.1 jetty-servlet-10.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-servlet/10.0.1/jetty-servlet-10.0.1.jar MD5: ea03b0705887afec566856a7f2f7ca42 SHA1: b4b796fbbdc90f7b8dfbfc81d799ff738ff53dd6 SHA256: 8f72368534a6a90130477d69911dd7744b521e9f56f80ebe70e82eb78cec5b66 pkg:maven/org.eclipse.jetty/jetty-servlet@10.0.1 jetty-security-10.0.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-security/10.0.1/jetty-security-10.0.1.jar MD5: 4e97ce76f92a1cad4020c19b79f366be SHA1: dd7b5540da2021db694c7db343e5bc75aba4f12f SHA256: d369c44565082bee7130192c958c4995c998f6682c35448a2690d07b0c86e103 pkg:maven/org.eclipse.jetty/jetty-security@10.0.1 Published Vulnerabilities CVE-2021-28163 suppress
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. CWE-59 Improper Link Resolution Before File Access ('Link Following')
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: LOW (2.7) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-28165 suppress
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: HIGH (7.8) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jetty-io-10.0.1.jarDescription:
Jetty module for Jetty :: IO Utility License:
https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0 File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-io/10.0.1/jetty-io-10.0.1.jar
MD5: 75b6e2dcd4ed97cfec4e3471a5921954
SHA1: c3a08489113d7717862c52686fea46dc7a5b8a83
SHA256: 7f140341ad0a328998ba974a6eeeec3354189fdd5852f10ed677f56d8e3be9e6
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium Vendor pom parent-groupid org.eclipse.jetty Medium Vendor Manifest url https://www.eclipse.org/jetty/ Low Vendor pom groupid eclipse.jetty Highest Vendor Manifest Implementation-Vendor Eclipse Jetty Project High Vendor jar package name io Highest Vendor pom parent-artifactid jetty-project Low Vendor file name jetty-io High Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Vendor pom name Jetty :: IO Utility High Vendor jar package name jetty Highest Vendor pom groupid org.eclipse.jetty Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Vendor pom artifactid jetty-io Low Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium Product pom parent-groupid org.eclipse.jetty Medium Product Manifest url https://www.eclipse.org/jetty/ Low Product pom artifactid jetty-io Highest Product pom groupid eclipse.jetty Highest Product jar package name io Highest Product file name jetty-io High Product pom parent-artifactid jetty-project Medium Product Manifest Bundle-Name Jetty :: IO Utility Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Product pom name Jetty :: IO Utility High Product jar package name jetty Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Version file version 10.0.1 High Version pom version 10.0.1 Highest Version Manifest Bundle-Version 10.0.1 High Version Manifest Implementation-Version 10.0.1 High
jetty-server-10.0.1.jarDescription:
The core jetty server artifact. License:
https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0 File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/jetty-server/10.0.1/jetty-server-10.0.1.jar
MD5: 4a44534049d5d57b3f117c375c577ffa
SHA1: 2bdf137df2e5f478b4e1a65cf284fc329b9e4d78
SHA256: eabe5a2cb803a5523030c36026048c3c2a4d49e881691915313627d6e224fbf0
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.eclipse.jetty Medium Vendor Manifest url https://www.eclipse.org/jetty/ Low Vendor pom groupid eclipse.jetty Highest Vendor Manifest Implementation-Vendor Eclipse Jetty Project High Vendor file name jetty-server High Vendor jar package name server Highest Vendor pom parent-artifactid jetty-project Low Vendor Manifest bundle-symbolicname org.eclipse.jetty.server Medium Vendor pom artifactid jetty-server Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Vendor jar package name jetty Highest Vendor pom groupid org.eclipse.jetty Highest Vendor pom name Jetty :: Server Core High Vendor Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Product Manifest Bundle-Name Jetty :: Server Core Medium Product pom parent-groupid org.eclipse.jetty Medium Product Manifest url https://www.eclipse.org/jetty/ Low Product pom groupid eclipse.jetty Highest Product file name jetty-server High Product jar package name server Highest Product pom parent-artifactid jetty-project Medium Product Manifest bundle-symbolicname org.eclipse.jetty.server Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-copyright Copyright (c) 2008-2021 Mort Bay Consulting Pty Ltd and others. Low Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org/jetty/ Low Product jar package name jetty Highest Product pom name Jetty :: Server Core High Product pom artifactid jetty-server Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Version file version 10.0.1 High Version pom version 10.0.1 Highest Version Manifest Bundle-Version 10.0.1 High Version Manifest Implementation-Version 10.0.1 High
Published Vulnerabilities CVE-2021-28163 suppress
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. CWE-59 Improper Link Resolution Before File Access ('Link Following')
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: LOW (2.7) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-28165 suppress
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: HIGH (7.8) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jetty-servlet-api-4.0.6.jarDescription:
Combined servlet api and schemas for use in JPMS and OSGi environments License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/jetty/toolchain/jetty-servlet-api/4.0.6/jetty-servlet-api-4.0.6.jar
MD5: d63413e02885c25d0129e3d2936606f6
SHA1: 959c5d83d08f5cddf56caff749e48b735193191b
SHA256: d90bf1f8a9d2ba89f4510bb51e1516dcf94ef6dc034e00f233654abdd78f2210
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom groupid org.eclipse.jetty.toolchain Highest Vendor file name jetty-servlet-api High Vendor jar package name servlet Highest Vendor pom groupid eclipse.jetty.toolchain Highest Vendor pom parent-groupid org.eclipse.jetty.toolchain Medium Vendor Manifest bundle-docurl https://eclipse.org/jetty Low Vendor Manifest bundle-symbolicname org.eclipse.jetty.servlet-api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom parent-artifactid jetty-toolchain Low Vendor pom name Jetty :: Servlet API and Schemas for JPMS and OSGi High Vendor pom artifactid jetty-servlet-api Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Product jar package name filter Highest Product pom parent-artifactid jetty-toolchain Medium Product file name jetty-servlet-api High Product jar package name servlet Highest Product pom groupid eclipse.jetty.toolchain Highest Product pom parent-groupid org.eclipse.jetty.toolchain Medium Product Manifest bundle-docurl https://eclipse.org/jetty Low Product Manifest Bundle-Name Eclipse Jetty Servlet API and Schemas for JPMS and OSGi Medium Product Manifest bundle-symbolicname org.eclipse.jetty.servlet-api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom name Jetty :: Servlet API and Schemas for JPMS and OSGi High Product Manifest build-jdk-spec 11 Low Product pom artifactid jetty-servlet-api Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-11 Low Version Manifest Bundle-Version 4.0.6 High Version pom parent-version 4.0.6 Low Version file version 4.0.6 High Version pom version 4.0.6 Highest
Published Vulnerabilities CVE-2009-5045 suppress
Dump Servlet information leak in jetty before 6.1.22. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2009-5046 suppress
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-7656 suppress
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-7657 suppress
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2017-7658 suppress
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2017-9735 suppress
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2020-27216 suppress
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
jsonld-java-0.8.3.jarDescription:
Json-LD core implementation License:
https://raw.github.com/jsonld-java/jsonld-java/master/LICENCE File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/github/jsonld-java/jsonld-java/0.8.3/jsonld-java-0.8.3.jar
MD5: 2bb1918de0760e21660f548cc5fedddf
SHA1: 214e8c5ac2ccadbf7c9c9f80ce8b720a5e0d6b25
SHA256: ee0affd3325c623dfef89c48ded3ea98a19bae90ba26ecd615358dd47cd311be
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname com.github.jsonld-java Medium Vendor pom parent-groupid com.github.jsonld-java Medium Vendor pom groupid com.github.jsonld-java Highest Vendor pom artifactid jsonld-java Low Vendor file name jsonld-java High Vendor pom parent-artifactid jsonld-java-parent Low Vendor jar package name github Highest Vendor pom name JSONLD Java :: Core High Vendor pom groupid github.jsonld-java Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name core Highest Product Manifest bundle-symbolicname com.github.jsonld-java Medium Product pom parent-groupid com.github.jsonld-java Medium Product pom artifactid jsonld-java Highest Product Manifest Bundle-Name JSONLD Java :: Core Medium Product pom parent-artifactid jsonld-java-parent Medium Product file name jsonld-java High Product jar package name github Highest Product pom name JSONLD Java :: Core High Product pom groupid github.jsonld-java Highest Product jar package name core Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Version pom version 0.8.3 Highest Version file version 0.8.3 High Version Manifest Bundle-Version 0.8.3 High
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jsr305 Low Vendor pom name FindBugs-jsr305 High Vendor pom url http://findbugs.sourceforge.net/ Highest Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor pom groupid google.code.findbugs Highest Vendor pom groupid com.google.code.findbugs Highest Vendor file name jsr305 High Product pom name FindBugs-jsr305 High Product Manifest bundle-symbolicname org.jsr-305 Medium Product Manifest Bundle-Name FindBugs-jsr305 Medium Product pom artifactid jsr305 Highest Product pom groupid google.code.findbugs Highest Product file name jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest Version file version 3.0.2 High
jul-to-slf4j-1.7.30.jarDescription:
JUL to SLF4J bridge File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/slf4j/jul-to-slf4j/1.7.30/jul-to-slf4j-1.7.30.jarMD5: f2c78cb93d70dc5dea0c50f36ace09c1SHA1: d58bebff8cbf70ff52b59208586095f467656c30SHA256: bbcbfdaa72572255c4f85207a9bfdb24358dc993e41252331bd4d0913e4988b9Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name bridge Highest Vendor pom url http://www.slf4j.org Highest Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom name JUL to SLF4J bridge High Vendor file name jul-to-slf4j High Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor pom parent-groupid org.slf4j Medium Vendor jar package name slf4j Highest Vendor pom artifactid jul-to-slf4j Low Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid slf4j Highest Product jar package name bridge Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom name JUL to SLF4J bridge High Product file name jul-to-slf4j High Product Manifest Bundle-Name jul-to-slf4j Medium Product Manifest bundle-symbolicname jul.to.slf4j Medium Product pom parent-artifactid slf4j-parent Medium Product pom artifactid jul-to-slf4j Highest Product pom parent-groupid org.slf4j Medium Product jar package name slf4j Highest Product pom url http://www.slf4j.org Medium Product pom groupid slf4j Highest Version Manifest Implementation-Version 1.7.30 High Version Manifest Bundle-Version 1.7.30 High Version pom version 1.7.30 Highest Version file version 1.7.30 High
logback-core-1.2.3.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/ch/qos/logback/logback-core/1.2.3/logback-core-1.2.3.jar
MD5: 841fc80c6edff60d947a3872a2db4d45
SHA1: 864344400c3d4d92dfeb0a305dc87d953677c03c
SHA256: 5946d837fe6f960c02a53eda7a6926ecc3c758bbdd69aa453ee429f858217f22
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name logback-core High Vendor pom parent-artifactid logback-parent Low Vendor jar package name logback Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name qos Highest Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor pom artifactid logback-core Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor pom name Logback Core Module High Vendor pom groupid ch.qos.logback Highest Vendor jar package name ch Highest Vendor jar package name core Highest Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Product file name logback-core High Product pom parent-artifactid logback-parent Medium Product Manifest Bundle-Name Logback Core Module Medium Product jar package name logback Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product jar package name qos Highest Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom name Logback Core Module High Product jar package name ch Highest Product pom groupid ch.qos.logback Highest Product pom artifactid logback-core Highest Product jar package name core Highest Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Version Manifest Bundle-Version 1.2.3 High Version pom version 1.2.3 Highest Version file version 1.2.3 High
Related Dependencies logback-classic-1.2.3.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/ch/qos/logback/logback-classic/1.2.3/logback-classic-1.2.3.jar MD5: 64f7a68f931aed8e5ad8243470440f0b SHA1: 7c4f3c474fb2c041d8028740440937705ebb473a SHA256: fb53f8539e7fcb8f093a56e138112056ec1dc809ebb020b59d8a36a5ebac37e0 pkg:maven/ch.qos.logback/logback-classic@1.2.3 lombok-1.18.18.jarDescription:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more! License:
The MIT License: https://projectlombok.org/LICENSE File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/projectlombok/lombok/1.18.18/lombok-1.18.18.jar
MD5: 6a157cf72924f8d135dcd6c571bf0405
SHA1: 481f5bfed3ae29f656eedfe9e98c8365b8ba5c57
SHA256: 601ec46206e0f9cac2c0583b3350e79f095419c395e991c761640f929038e9cc
Referenced In Project/Scope: blueMarine II :: Headless Service:provided
Evidence Type Source Name Value Confidence Vendor pom groupid org.projectlombok Highest Vendor jar package name java Highest Vendor jar package name lombok Highest Vendor pom artifactid lombok Low Vendor pom name Project Lombok High Vendor jar package name tostring Highest Vendor file name lombok High Vendor pom url https://projectlombok.org Highest Vendor Manifest can-redefine-classes true Low Vendor Manifest automatic-module-name lombok Medium Vendor pom groupid projectlombok Highest Product jar package name java Highest Product jar package name lombok Highest Product pom name Project Lombok High Product jar package name tostring Highest Product file name lombok High Product Manifest can-redefine-classes true Low Product pom artifactid lombok Highest Product pom url https://projectlombok.org Medium Product Manifest automatic-module-name lombok Medium Product pom groupid projectlombok Highest Version file version 1.18.18 High Version Manifest lombok-version 1.18.18 Medium Version pom version 1.18.18 Highest
mapdb-1.0.8.jarDescription:
MapDB provides concurrent Maps, Sets and Queues backed by disk storage or off-heap memory. It is a fast, scalable and easy to use embedded Java database. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/mapdb/mapdb/1.0.8/mapdb-1.0.8.jar
MD5: aaea7b500b214a08b2dc61d38d04024e
SHA1: 64485a221d9095fc7ab9b50cc34c6b4b58467e2e
SHA256: e757738f3a0867d7d9a1f1532bf7ca09eab02f032767eb403c991cb4e09c4fe0
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.mapdb Highest Vendor pom url http://www.mapdb.org Highest Vendor pom groupid mapdb Highest Vendor Manifest bundle-symbolicname org.mapdb.mapdb Medium Vendor jar package name queues Highest Vendor pom name mapdb High Vendor jar package name mapdb Highest Vendor file name mapdb High Vendor pom artifactid mapdb Low Product pom artifactid mapdb Highest Product pom groupid mapdb Highest Product pom url http://www.mapdb.org Medium Product jar package name queues Highest Product Manifest bundle-symbolicname org.mapdb.mapdb Medium Product pom name mapdb High Product jar package name mapdb Highest Product Manifest Bundle-Name mapdb Medium Product file name mapdb High Version file version 1.0.8 High Version pom version 1.0.8 Highest Version Manifest Bundle-Version 1.0.8 High
opencsv-3.2.jarDescription:
A simple library for reading and writing CSV in Java License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/opencsv/opencsv/3.2/opencsv-3.2.jar
MD5: ae00a81a37f8a4102b5d265e7d5a872e
SHA1: 11986807ecb3288728bdb33a3165ce84f057d7a4
SHA256: 8da30a0838a09ae8a3d4e8bffa42a787ec462dfe824da043d1d625ae7e4c7c94
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name opencsv Highest Vendor pom groupid opencsv Highest Vendor pom groupid com.opencsv Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid opencsv Low Vendor Manifest bundle-symbolicname com.opencsv Medium Vendor file name opencsv High Vendor pom name opencsv High Vendor pom url http://opencsv.sf.net Highest Product pom artifactid opencsv Highest Product pom url http://opencsv.sf.net Medium Product jar package name opencsv Highest Product pom groupid opencsv Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest bundle-symbolicname com.opencsv Medium Product file name opencsv High Product pom name opencsv High Product Manifest Bundle-Name opencsv Medium Version pom version 3.2 Highest Version file version 3.2 High
rdf4j-spin-2.1.4.jarDescription:
SPARQL input notation interfaces and implementations File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/eclipse/rdf4j/rdf4j-spin/2.1.4/rdf4j-spin-2.1.4.jarMD5: 4cf3ed3b0340e6701e99e59b6bf127bdSHA1: bc0a1f5bea07048cac86e4c570faaf5bace180b1SHA256: df8614f35f6eeb51fc49cb09cba85116cb0c0a19019db99f5e64338b2944600eReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid rdf4j-core Low Vendor file name rdf4j-spin High Vendor jar package name spin Low Vendor pom groupid org.eclipse.rdf4j Highest Vendor jar package name eclipse Low Vendor jar package name rdf4j Low Vendor pom artifactid rdf4j-spin Low Vendor pom groupid eclipse.rdf4j Highest Vendor pom name RDF4J: SPIN High Vendor jar package name rdf4j Highest Vendor jar package name eclipse Highest Vendor pom parent-groupid org.eclipse.rdf4j Medium Vendor jar package name spin Highest Product jar package name function Low Product file name rdf4j-spin High Product jar package name spin Low Product jar package name rdf4j Low Product pom groupid eclipse.rdf4j Highest Product pom parent-artifactid rdf4j-core Medium Product pom name RDF4J: SPIN High Product jar package name rdf4j Highest Product jar package name eclipse Highest Product pom artifactid rdf4j-spin Highest Product pom parent-groupid org.eclipse.rdf4j Medium Product jar package name spin Highest Version pom version 2.1.4 Highest Version file version 2.1.4 High
Related Dependencies Published Vulnerabilities CVE-2018-1000644 suppress
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (10.0) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
seamless-http-1.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/seamless/seamless-http/1.1.1/seamless-http-1.1.1.jarMD5: 1928a351212b418631309c33e7036753SHA1: 18cc72baf8fbb8f85993dfc4e252c5b6b8cc0139SHA256: 05da30fa260cf53770fefbd46482c04f6a37e19b663fec282a4c4384c0def813Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name http Highest Vendor pom parent-artifactid parent Low Vendor file name seamless-http High Vendor pom name Seamless HTTP High Vendor pom artifactid seamless-http Low Vendor pom groupid org.seamless Highest Vendor pom groupid seamless Highest Vendor jar package name seamless Highest Vendor jar package name seamless Low Vendor pom parent-groupid org.seamless Medium Vendor jar package name http Low Product pom artifactid seamless-http Highest Product jar package name http Highest Product file name seamless-http High Product pom name Seamless HTTP High Product pom parent-artifactid parent Medium Product pom groupid seamless Highest Product jar package name seamless Highest Product pom parent-groupid org.seamless Medium Product jar package name http Low Version pom version 1.1.1 Highest Version file version 1.1.1 High
seamless-swing-1.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/seamless/seamless-swing/1.1.1/seamless-swing-1.1.1.jarMD5: 68b88b69dde7a8067a0d8e7d5d7fa9e8SHA1: 0dd7141e863a53f0e7210147d5ab39c626546493SHA256: 653fa6fea357f1349075bdd94328fc9c0d285046d7deb25a56dc8a86513b64e0Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom name Seamless Swing High Vendor file name seamless-swing High Vendor jar package name swing Highest Vendor pom groupid org.seamless Highest Vendor jar package name seamless Highest Vendor jar package name seamless Low Vendor jar package name swing Low Vendor jar package name logging Low Vendor pom parent-artifactid parent Low Vendor pom groupid seamless Highest Vendor pom artifactid seamless-swing Low Vendor pom parent-groupid org.seamless Medium Product jar package name swing Low Product jar package name logging Low Product pom name Seamless Swing High Product pom artifactid seamless-swing Highest Product file name seamless-swing High Product jar package name swing Highest Product pom parent-artifactid parent Medium Product pom groupid seamless Highest Product jar package name seamless Highest Product pom parent-groupid org.seamless Medium Version pom version 1.1.1 Highest Version file version 1.1.1 High
seamless-util-1.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/seamless/seamless-util/1.1.1/seamless-util-1.1.1.jarMD5: e2bf5ce54b06a7cf06fea4ded6fb44fdSHA1: 989fb6690245740d76ed08634c04610f52ca1e2aSHA256: eb663e3739d67137baab18e65ed2cdec28213a8871458323c3cc62da085cec3cReferenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name util Highest Vendor file name seamless-util High Vendor pom parent-artifactid parent Low Vendor jar package name util Low Vendor pom artifactid seamless-util Low Vendor pom groupid org.seamless Highest Vendor pom groupid seamless Highest Vendor jar package name seamless Highest Vendor jar package name seamless Low Vendor pom name Seamless Utilities High Vendor pom parent-groupid org.seamless Medium Product pom artifactid seamless-util Highest Product jar package name util Highest Product file name seamless-util High Product jar package name util Low Product pom parent-artifactid parent Medium Product pom groupid seamless Highest Product jar package name seamless Highest Product pom name Seamless Utilities High Product pom parent-groupid org.seamless Medium Version pom version 1.1.1 Highest Version file version 1.1.1 High
seamless-xml-1.1.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/seamless/seamless-xml/1.1.1/seamless-xml-1.1.1.jarMD5: ce48d7a6ba4e759283b26b9b2b084445SHA1: ddc628b23904faf124b84f768e9caa03147da5abSHA256: 6d80a97918e4ae91ecb676f9cd056942f1565d981d054a461058a16096464298Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor pom name Seamless XML High Vendor jar package name xml Highest Vendor file name seamless-xml High Vendor pom parent-artifactid parent Low Vendor pom groupid org.seamless Highest Vendor pom groupid seamless Highest Vendor pom artifactid seamless-xml Low Vendor jar package name seamless Highest Vendor jar package name seamless Low Vendor pom parent-groupid org.seamless Medium Vendor jar package name xhtml Low Product pom artifactid seamless-xml Highest Product pom name Seamless XML High Product jar package name xml Highest Product file name seamless-xml High Product pom parent-artifactid parent Medium Product pom groupid seamless Highest Product jar package name seamless Highest Product pom parent-groupid org.seamless Medium Product jar package name xhtml Low Version pom version 1.1.1 Highest Version file version 1.1.1 High
slf4j-api-1.7.30.jarDescription:
The slf4j API File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/slf4j/slf4j-api/1.7.30/slf4j-api-1.7.30.jarMD5: f8be00da99bc4ab64c79ab1e2be7cb7cSHA1: b5a4b6d16ab13e34a88fae84c35cd5d68cac922cSHA256: cdba07964d1bb40a0761485c6b1e8c2f8fd9eb1d19c53928ac0d7f9510105c57Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://www.slf4j.org Highest Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor file name slf4j-api High Vendor pom parent-groupid org.slf4j Medium Vendor pom artifactid slf4j-api Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor jar package name slf4j Highest Vendor pom name SLF4J API Module High Vendor Manifest automatic-module-name org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid slf4j Highest Product Manifest Implementation-Title slf4j-api High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product file name slf4j-api High Product Manifest Bundle-Name slf4j-api Medium Product pom parent-artifactid slf4j-parent Medium Product pom parent-groupid org.slf4j Medium Product jar package name slf4j Highest Product Manifest bundle-symbolicname slf4j.api Medium Product pom name SLF4J API Module High Product pom artifactid slf4j-api Highest Product Manifest automatic-module-name org.slf4j Medium Product pom url http://www.slf4j.org Medium Product pom groupid slf4j Highest Version Manifest Implementation-Version 1.7.30 High Version Manifest Bundle-Version 1.7.30 High Version pom version 1.7.30 Highest Version file version 1.7.30 High
spatial4j-0.4.1.jarDescription:
Spatial4j is a general purpose spatial / geospatial ASL licensed open-source Java library. It's
core capabilities are 3-fold: to provide common geospatially-aware shapes, to provide distance
calculations and other math, and to read shapes in WKT format.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/spatial4j/spatial4j/0.4.1/spatial4j-0.4.1.jar
MD5: 7eafc2e18e82d7a38cb800be2dc9d678
SHA1: 4234d12b1ba4d4b539fb3e29edd948a99539d9eb
SHA256: c467b888bf475495a86a0f4491cb87f80f584e7646cafc7686489f81bce371bc
Referenced In Project/Scope: blueMarine II :: Headless Service:runtime
Evidence Type Source Name Value Confidence Vendor file name spatial4j High Vendor pom organization name LocationTech High Vendor Manifest bundle-symbolicname com.spatial4j Medium Vendor pom url spatial4j/spatial4j Highest Vendor Manifest bundle-docurl http://locationtech.org Low Vendor pom name Spatial4J High Vendor pom groupid com.spatial4j Highest Vendor pom artifactid spatial4j Low Vendor jar package name spatial4j Highest Vendor jar package name distance Highest Vendor pom groupid spatial4j Highest Vendor pom organization url http://locationtech.org Medium Vendor jar package name core Highest Product file name spatial4j High Product pom url spatial4j/spatial4j High Product Manifest bundle-symbolicname com.spatial4j Medium Product pom artifactid spatial4j Highest Product Manifest bundle-docurl http://locationtech.org Low Product pom organization name LocationTech Low Product pom name Spatial4J High Product jar package name spatial4j Highest Product jar package name distance Highest Product Manifest Bundle-Name Spatial4J Medium Product pom groupid spatial4j Highest Product jar package name core Highest Product pom organization url http://locationtech.org Low Version file version 0.4.1 High Version pom version 0.4.1 Highest Version Manifest Bundle-Version 0.4.1 High
spotbugs-annotations-3.1.9.jarDescription:
Annotations the SpotBugs tool supports License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/com/github/spotbugs/spotbugs-annotations/3.1.9/spotbugs-annotations-3.1.9.jar
MD5: 56a1a81d69b6a111161bbce0e6dea26a
SHA1: 2ef5127efcc1a899aab8c66d449a631c9a99c469
SHA256: 68c7c46b4299e94837e236ae742f399901a950fe910fe3ca710026753b5dd2e1
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor pom name SpotBugs Annotations High Vendor file name spotbugs-annotations High Vendor pom groupid com.github.spotbugs Highest Vendor pom artifactid spotbugs-annotations Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname spotbugs-annotations Medium Vendor pom url https://spotbugs.github.io/ Highest Vendor Manifest automatic-module-name com.github.spotbugs.annotations Medium Vendor pom groupid github.spotbugs Highest Product pom name SpotBugs Annotations High Product file name spotbugs-annotations High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname spotbugs-annotations Medium Product Manifest Bundle-Name spotbugs-annotations Medium Product pom url https://spotbugs.github.io/ Medium Product pom artifactid spotbugs-annotations Highest Product Manifest automatic-module-name com.github.spotbugs.annotations Medium Product pom groupid github.spotbugs Highest Version file version 3.1.9 High Version Manifest Bundle-Version 3.1.9 High Version pom version 3.1.9 Highest
spring-core-5.3.1.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-core/5.3.1/spring-core-5.3.1.jar
MD5: df36706fc74458c9c28e97aca7fae409
SHA1: 47af5b161749cd249fc074b4f140e011a3337efd
SHA256: 6ee995055163c59703be237be59f0565acb97c9d42c5d60df2bf3a4b4c6ef6e9
Referenced In Project/Scope: blueMarine II :: Headless Service:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.core Medium Vendor pom url spring-projects/spring-framework Highest Vendor pom artifactid spring-core Low Vendor jar package name io Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom name Spring Core High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom groupid org.springframework Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom organization name Spring IO High Vendor pom groupid springframework Highest Vendor jar package name core Highest Vendor file name spring-core High Product Manifest automatic-module-name spring.core Medium Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Product pom artifactid spring-core Highest Product jar package name io Highest Product pom name Spring Core High Product Manifest Implementation-Title spring-core High Product pom organization name Spring IO Low Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product pom groupid springframework Highest Product jar package name core Highest Product file name spring-core High Version file version 5.3.1 High Version Manifest Implementation-Version 5.3.1 High Version pom version 5.3.1 Highest
Related Dependencies spring-jcl-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-jcl/5.3.1/spring-jcl-5.3.1.jar MD5: 5a4890886c1d3540e3b52a0ae3f6b850 SHA1: 1158888aa7517f8997eb43afe47776d9d2de8a38 SHA256: 31081cbd5bdfb2cc80d50f11d59deb6a410b1f21593af9e20f6ec6b4c0fe220d pkg:maven/org.springframework/spring-jcl@5.3.1 spring-webmvc-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-webmvc/5.3.1/spring-webmvc-5.3.1.jar MD5: c0c5785e768fababd9414a66545d022b SHA1: 17493978f251b7e51393cdf19f4f51af9c1f04f2 SHA256: 565b5e4503a4a427bd46520a432e39233b1d93d307c85d050afa29904b7e836b pkg:maven/org.springframework/spring-webmvc@5.3.1 spring-expression-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-expression/5.3.1/spring-expression-5.3.1.jar MD5: d465932c5f36eed42ae9958fed2a098c SHA1: aee660842a21fbf49f6e5921aa07974f1650c498 SHA256: 897f79c85ba4fb3ed7a086a982c909d5aba9161c4d8707b00868fa27403256b8 pkg:maven/org.springframework/spring-expression@5.3.1 spring-aop-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-aop/5.3.1/spring-aop-5.3.1.jar MD5: f08cd6faaf67d097bc4fbdf9684f325c SHA1: 25c310880484082ffba3130deb8e10c5afb29f10 SHA256: a1f67fe0a11341c7da562053a74457191ead48db8ee49b7713f65c383c8b9526 pkg:maven/org.springframework/spring-aop@5.3.1 spring-aspects-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-aspects/5.3.1/spring-aspects-5.3.1.jar MD5: f364d6228c719936bc8751e997cb861d SHA1: 968c9205f85589b5c102b3232f499fa90ec28a48 SHA256: 962195358fdd97d30204d5ad75dd9339c3f1db7e008ab106b524197a4889ac96 pkg:maven/org.springframework/spring-aspects@5.3.1 spring-context-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-context/5.3.1/spring-context-5.3.1.jar MD5: bd13eda44ac28f87d752abaf0bbd5325 SHA1: 736836c8098981ddabd309a0c15f967594da62bc SHA256: 5adcc88fc791d012e0993e2f5d3770e03c2432df5a561c63bfa9e1dc6ac93501 pkg:maven/org.springframework/spring-context@5.3.1 spring-web-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-web/5.3.1/spring-web-5.3.1.jar MD5: 2c074c8766b7fb749bdad2332d61d7f5 SHA1: 4e1e1d1c6b5a00597162db84132414c409bcf615 SHA256: 925f3b82035f31b410309154c3ae1e48ffa5204280275bdc9390d91312ad4fb4 pkg:maven/org.springframework/spring-web@5.3.1 spring-beans-5.3.1.jarFile Path: /Volumes/Users/fritz/LocalData/Business/Tidalwave/Projects/WorkAreas/tidalwave.bitbucket.io/repository/org/springframework/spring-beans/5.3.1/spring-beans-5.3.1.jar MD5: 8218016c1dfa50b56eb65bb7415db575 SHA1: a4bb5ffad5564e4a0e25955e3a40b1c6158385b2 SHA256: 86f7c1cdac78f5fe6e2547d8faef52e8c3528526563b542c4922479f5422c440 pkg:maven/org.springframework/spring-beans@5.3.1