SamHeadrickCx / JavaVulnerableLab-1

lab
GNU General Public License v2.0
0 stars 0 forks source link

branch10 #80

Open SamHeadrickCx opened 1 month ago

SamHeadrickCx commented 1 month ago

branch10

github-actions[bot] commented 1 month ago

Scan submitted to Checkmarx

github-actions[bot] commented 1 month ago

Logo Checkmarx SCA - Scan Summary & Details

Cx-SCA Summary

Total Packages Identified: 24 Scan Risk Score: 9.80

Critical 0 Critical severity vulnerabilities High 55 High severity vulnerabilities Medium 31 Medium severity vulnerabilities Low 3 Low severity vulnerabilities View more details on Checkmarx UI

Cx-SCA vulnerability result overview

Click to see details |Vulnerability ID|Package|Severity|CVSS score|Publish date|Current version|Recommended version|Link in CxSCA|Reference – NVD link| ---|---|---|---|---|---|---|---|--- `CVE-2015-7501`|commons-collections:commons-collections|HIGH|9.8|2017-11-09T17:29:00|3.2.1|3.2.2| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2015-7501%3AMaven-commons-collections%3Acommons-collections-3.2.1/vulnerabilityDetailsGql)|[CVE-2015-7501](https://nvd.nist.gov/vuln/detail/CVE-2015-7501) `CVE-2016-2170`|commons-collections:commons-collections|HIGH|9.8|2016-04-12T14:59:00|3.2.1|3.2.2| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2016-2170%3AMaven-commons-collections%3Acommons-collections-3.2.1/vulnerabilityDetailsGql)|[CVE-2016-2170](https://nvd.nist.gov/vuln/detail/CVE-2016-2170) `CVE-2015-4852`|commons-collections:commons-collections|HIGH|9.8|2015-11-18T15:59:00|3.2.1|3.2.2| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2015-4852%3AMaven-commons-collections%3Acommons-collections-3.2.1/vulnerabilityDetailsGql)|[CVE-2015-4852](https://nvd.nist.gov/vuln/detail/CVE-2015-4852) `CVE-2020-10683`|dom4j:dom4j|HIGH|9.8|2020-05-01T19:15:00|1.6.1|No Recommendations| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-10683%3AMaven-dom4j%3Adom4j-1.6.1/vulnerabilityDetailsGql)|[CVE-2020-10683](https://nvd.nist.gov/vuln/detail/CVE-2020-10683) `CVE-2019-10212`|io.undertow:undertow-core|HIGH|9.8|2019-10-02T19:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-10212%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2019-10212](https://nvd.nist.gov/vuln/detail/CVE-2019-10212) `CVE-2020-1745`|io.undertow:undertow-core|HIGH|9.8|2020-04-28T15:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-1745%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-1745](https://nvd.nist.gov/vuln/detail/CVE-2020-1745) `CVE-2019-3888`|io.undertow:undertow-core|HIGH|9.8|2019-06-12T14:29:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-3888%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2019-3888](https://nvd.nist.gov/vuln/detail/CVE-2019-3888) `CVE-2020-1938`|org.apache.tomcat:tomcat-coyote|HIGH|9.8|2020-02-24T22:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-1938%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-1938](https://nvd.nist.gov/vuln/detail/CVE-2020-1938) `CVE-2015-2575`|mysql:mysql-connector-java|HIGH|9.1|2014-12-06T00:00:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2015-2575%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2015-2575](https://nvd.nist.gov/vuln/detail/CVE-2015-2575) `CVE-2018-3258`|mysql:mysql-connector-java|HIGH|8.8|2018-10-17T01:31:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2018-3258%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2018-3258](https://nvd.nist.gov/vuln/detail/CVE-2018-3258) `CVE-2017-3523`|mysql:mysql-connector-java|HIGH|8.5|2017-04-24T19:59:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2017-3523%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2017-3523](https://nvd.nist.gov/vuln/detail/CVE-2017-3523) `CVE-2020-1757`|io.undertow:undertow-core|HIGH|8.1|2020-04-21T17:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-1757%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-1757](https://nvd.nist.gov/vuln/detail/CVE-2020-1757) `Cx78f40514-81ff`|commons-collections:commons-collections|HIGH|7.5|2018-10-31T10:39:00|3.2.1|No Recommendations| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx78f40514-81ff%3AMaven-commons-collections%3Acommons-collections-3.2.1/vulnerabilityDetailsGql)|[Cx78f40514-81ff](https://nvd.nist.gov/vuln/detail/Cx78f40514-81ff) `CVE-2015-6420`|commons-collections:commons-collections|HIGH|7.5|2015-12-15T05:59:00|3.2.1|3.2.2| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2015-6420%3AMaven-commons-collections%3Acommons-collections-3.2.1/vulnerabilityDetailsGql)|[CVE-2015-6420](https://nvd.nist.gov/vuln/detail/CVE-2015-6420) `CVE-2018-1000632`|dom4j:dom4j|HIGH|7.5|2018-08-20T19:31:00|1.6.1|No Recommendations| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2018-1000632%3AMaven-dom4j%3Adom4j-1.6.1/vulnerabilityDetailsGql)|[CVE-2018-1000632](https://nvd.nist.gov/vuln/detail/CVE-2018-1000632) `CVE-2022-4492`|io.undertow:undertow-core|HIGH|7.5|2023-02-23T20:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-4492%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2022-4492](https://nvd.nist.gov/vuln/detail/CVE-2022-4492) `CVE-2023-3223`|io.undertow:undertow-core|HIGH|7.5|2023-09-27T15:18:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-3223%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2023-3223](https://nvd.nist.gov/vuln/detail/CVE-2023-3223) `CVE-2024-7885`|io.undertow:undertow-core|HIGH|7.5|2024-08-21T14:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-7885%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-7885](https://nvd.nist.gov/vuln/detail/CVE-2024-7885) `CVE-2021-3859`|io.undertow:undertow-core|HIGH|7.5|2022-08-25T23:09:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-3859%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2021-3859](https://nvd.nist.gov/vuln/detail/CVE-2021-3859) `CVE-2023-5379`|io.undertow:undertow-core|HIGH|7.5|2023-12-12T22:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-5379%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2023-5379](https://nvd.nist.gov/vuln/detail/CVE-2023-5379) `CVE-2022-1319`|io.undertow:undertow-core|HIGH|7.5|2022-08-31T16:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-1319%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2022-1319](https://nvd.nist.gov/vuln/detail/CVE-2022-1319) `CVE-2023-1973`|io.undertow:undertow-core|HIGH|7.5|2024-04-05T09:44:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-1973%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2023-1973](https://nvd.nist.gov/vuln/detail/CVE-2023-1973) `CVE-2022-2053`|io.undertow:undertow-core|HIGH|7.5|2022-08-05T10:13:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-2053%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2022-2053](https://nvd.nist.gov/vuln/detail/CVE-2022-2053) `CVE-2020-10705`|io.undertow:undertow-core|HIGH|7.5|2020-06-10T20:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-10705%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-10705](https://nvd.nist.gov/vuln/detail/CVE-2020-10705) `CVE-2024-6162`|io.undertow:undertow-core|HIGH|7.5|2024-06-20T15:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-6162%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-6162](https://nvd.nist.gov/vuln/detail/CVE-2024-6162) `CVE-2024-5971`|io.undertow:undertow-core|HIGH|7.5|2024-07-08T21:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-5971%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-5971](https://nvd.nist.gov/vuln/detail/CVE-2024-5971) `CVE-2020-27782`|io.undertow:undertow-core|HIGH|7.5|2021-02-23T19:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-27782%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-27782](https://nvd.nist.gov/vuln/detail/CVE-2020-27782) `CVE-2024-1635`|io.undertow:undertow-core|HIGH|7.5|2024-02-19T22:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-1635%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-1635](https://nvd.nist.gov/vuln/detail/CVE-2024-1635) `CVE-2023-1108`|io.undertow:undertow-core|HIGH|7.5|2023-09-14T15:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-1108%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2023-1108](https://nvd.nist.gov/vuln/detail/CVE-2023-1108) `CVE-2021-3690`|io.undertow:undertow-core|HIGH|7.5|2022-08-23T17:35:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-3690%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2021-3690](https://nvd.nist.gov/vuln/detail/CVE-2021-3690) `Cx6f651376-312a`|mysql:mysql-connector-java|HIGH|7.5|2017-08-14T23:00:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx6f651376-312a%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[Cx6f651376-312a](https://nvd.nist.gov/vuln/detail/Cx6f651376-312a) `Cx039cb67c-ead3`|mysql:mysql-connector-java|HIGH|7.5|2015-08-16T23:00:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx039cb67c-ead3%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[Cx039cb67c-ead3](https://nvd.nist.gov/vuln/detail/Cx039cb67c-ead3) `Cx7ef609d2-efb5`|mysql:mysql-connector-java|HIGH|7.5|2010-08-01T23:00:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx7ef609d2-efb5%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[Cx7ef609d2-efb5](https://nvd.nist.gov/vuln/detail/Cx7ef609d2-efb5) `CVE-2021-30639`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2021-07-12T15:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-30639%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2021-30639](https://nvd.nist.gov/vuln/detail/CVE-2021-30639) `CVE-2020-11996`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2020-06-26T17:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-11996%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-11996](https://nvd.nist.gov/vuln/detail/CVE-2020-11996) `CVE-2020-13934`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2020-07-14T15:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-13934%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-13934](https://nvd.nist.gov/vuln/detail/CVE-2020-13934) `CVE-2020-17527`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2020-12-03T19:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-17527%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-17527](https://nvd.nist.gov/vuln/detail/CVE-2020-17527) `CVE-2021-25122`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2021-03-01T12:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-25122%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2021-25122](https://nvd.nist.gov/vuln/detail/CVE-2021-25122) `CVE-2021-41079`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2021-09-16T15:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-41079%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2021-41079](https://nvd.nist.gov/vuln/detail/CVE-2021-41079) `CVE-2022-42252`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2022-11-01T09:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-42252%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2022-42252](https://nvd.nist.gov/vuln/detail/CVE-2022-42252) `CVE-2023-24998`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2023-02-20T16:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-24998%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2023-24998](https://nvd.nist.gov/vuln/detail/CVE-2023-24998) `CVE-2023-44487`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2023-10-10T09:17:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-44487%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487) `CVE-2024-24549`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2024-03-13T16:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-24549%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2024-24549](https://nvd.nist.gov/vuln/detail/CVE-2024-24549) `CVE-2024-34750`|org.apache.tomcat:tomcat-coyote|HIGH|7.5|2024-07-03T20:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-34750%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2024-34750](https://nvd.nist.gov/vuln/detail/CVE-2024-34750) `CVE-2023-5685`|org.jboss.xnio:xnio-api|HIGH|7.5|2024-03-22T19:15:00|3.3.8.Final|3.8.11.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-5685%3AMaven-org.jboss.xnio%3Axnio-api-3.3.8.Final/vulnerabilityDetailsGql)|[CVE-2023-5685](https://nvd.nist.gov/vuln/detail/CVE-2023-5685) `CVE-2022-0084`|org.jboss.xnio:xnio-api|HIGH|7.5|2022-08-26T05:53:00|3.3.8.Final|3.8.11.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-0084%3AMaven-org.jboss.xnio%3Axnio-api-3.3.8.Final/vulnerabilityDetailsGql)|[CVE-2022-0084](https://nvd.nist.gov/vuln/detail/CVE-2022-0084) `CVE-2022-45689`|org.json:json|HIGH|7.5|2022-12-13T15:15:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-45689%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[CVE-2022-45689](https://nvd.nist.gov/vuln/detail/CVE-2022-45689) `CVE-2022-45690`|org.json:json|HIGH|7.5|2022-12-13T15:15:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-45690%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[CVE-2022-45690](https://nvd.nist.gov/vuln/detail/CVE-2022-45690) `Cx08fcacc9-cb99`|org.json:json|HIGH|7.5|2017-10-30T11:27:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx08fcacc9-cb99%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[Cx08fcacc9-cb99](https://nvd.nist.gov/vuln/detail/Cx08fcacc9-cb99) `CVE-2022-45688`|org.json:json|HIGH|7.5|2022-12-13T15:15:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-45688%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[CVE-2022-45688](https://nvd.nist.gov/vuln/detail/CVE-2022-45688) `Cx2906ba70-607a`|org.json:json|HIGH|7.5|2017-08-18T09:31:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cx2906ba70-607a%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[Cx2906ba70-607a](https://nvd.nist.gov/vuln/detail/Cx2906ba70-607a) `CVE-2023-5072`|org.json:json|HIGH|7.5|2023-10-12T06:16:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-5072%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[CVE-2023-5072](https://nvd.nist.gov/vuln/detail/CVE-2023-5072) `Cxdb5a1032-eda2`|org.json:json|HIGH|7.5|2019-09-17T10:37:00|20131018|20231013| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cxdb5a1032-eda2%3AMaven-org.json%3Ajson-20131018/vulnerabilityDetailsGql)|[Cxdb5a1032-eda2](https://nvd.nist.gov/vuln/detail/Cxdb5a1032-eda2) `CVE-2016-10707`|jquery|HIGH|7.5|2018-01-18T23:29:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2016-10707%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2016-10707](https://nvd.nist.gov/vuln/detail/CVE-2016-10707) `CVE-2020-25638`|org.hibernate:hibernate-core|HIGH|7.4|2020-09-22T16:32:00|4.0.1.Final|4.1.3.Final-redhat-1| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-25638%3AMaven-org.hibernate%3Ahibernate-core-4.0.1.Final/vulnerabilityDetailsGql)|[CVE-2020-25638](https://nvd.nist.gov/vuln/detail/CVE-2020-25638) `CVE-2022-21363`|mysql:mysql-connector-java|MEDIUM|6.6|2022-01-19T12:15:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-21363%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2022-21363](https://nvd.nist.gov/vuln/detail/CVE-2022-21363) `CVE-2020-10719`|io.undertow:undertow-core|MEDIUM|6.5|2020-05-26T16:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-10719%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-10719](https://nvd.nist.gov/vuln/detail/CVE-2020-10719) `CVE-2019-14900`|org.hibernate:hibernate-core|MEDIUM|6.5|2019-01-15T00:00:00|4.0.1.Final|4.1.3.Final-redhat-1| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-14900%3AMaven-org.hibernate%3Ahibernate-core-4.0.1.Final/vulnerabilityDetailsGql)|[CVE-2019-14900](https://nvd.nist.gov/vuln/detail/CVE-2019-14900) `CVE-2017-3586`|mysql:mysql-connector-java|MEDIUM|6.4|2017-04-24T19:59:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2017-3586%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2017-3586](https://nvd.nist.gov/vuln/detail/CVE-2017-3586) `CVE-2019-2692`|mysql:mysql-connector-java|MEDIUM|6.3|2019-04-23T19:32:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-2692%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2019-2692](https://nvd.nist.gov/vuln/detail/CVE-2019-2692) `CVE-2020-11023`|jquery|MEDIUM|6.1|2020-04-29T15:45:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-11023%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2020-11023](https://nvd.nist.gov/vuln/detail/CVE-2020-11023) `CVE-2015-9251`|jquery|MEDIUM|6.1|2018-01-18T23:29:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2015-9251%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2015-9251](https://nvd.nist.gov/vuln/detail/CVE-2015-9251) `Cxf0b588a3-5c6f`|jquery|MEDIUM|6.1|2012-06-25T12:52:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/Cxf0b588a3-5c6f%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[Cxf0b588a3-5c6f](https://nvd.nist.gov/vuln/detail/Cxf0b588a3-5c6f) `CVE-2020-7656`|jquery|MEDIUM|6.1|2020-05-19T21:15:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-7656%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2020-7656](https://nvd.nist.gov/vuln/detail/CVE-2020-7656) `CVE-2020-11022`|jquery|MEDIUM|6.1|2020-04-29T22:15:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-11022%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2020-11022](https://nvd.nist.gov/vuln/detail/CVE-2020-11022) `CVE-2012-6708`|jquery|MEDIUM|6.1|2018-01-18T23:29:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2012-6708%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2012-6708](https://nvd.nist.gov/vuln/detail/CVE-2012-6708) `CVE-2019-11358`|jquery|MEDIUM|6.1|2019-04-20T00:29:00|1.6.4|3.5.0| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-11358%3ANpm-jquery-1.6.4/vulnerabilityDetailsGql)|[CVE-2019-11358](https://nvd.nist.gov/vuln/detail/CVE-2019-11358) `CVE-2021-3629`|io.undertow:undertow-core|MEDIUM|5.9|2022-05-24T19:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-3629%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2021-3629](https://nvd.nist.gov/vuln/detail/CVE-2021-3629) `CVE-2021-3597`|io.undertow:undertow-core|MEDIUM|5.9|2022-05-24T19:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-3597%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2021-3597](https://nvd.nist.gov/vuln/detail/CVE-2021-3597) `CVE-2021-2471`|mysql:mysql-connector-java|MEDIUM|5.9|2021-10-20T11:16:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-2471%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2021-2471](https://nvd.nist.gov/vuln/detail/CVE-2021-2471) `CVE-2020-14340`|org.jboss.xnio:xnio-nio|MEDIUM|5.9|2020-07-24T09:52:00|3.3.8.Final|3.4.7.Final-redhat-1| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-14340%3AMaven-org.jboss.xnio%3Axnio-nio-3.3.8.Final/vulnerabilityDetailsGql)|[CVE-2020-14340](https://nvd.nist.gov/vuln/detail/CVE-2020-14340) `CVE-2024-3653`|io.undertow:undertow-core|MEDIUM|5.3|2024-07-08T22:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-3653%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-3653](https://nvd.nist.gov/vuln/detail/CVE-2024-3653) `CVE-2024-1459`|io.undertow:undertow-core|MEDIUM|5.3|2024-02-12T21:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-1459%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2024-1459](https://nvd.nist.gov/vuln/detail/CVE-2024-1459) `CVE-2021-33037`|org.apache.tomcat:tomcat-coyote|MEDIUM|5.3|2021-07-12T15:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-33037%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2021-33037](https://nvd.nist.gov/vuln/detail/CVE-2021-33037) `CVE-2023-42795`|org.apache.tomcat:tomcat-coyote|MEDIUM|5.3|2023-10-10T08:59:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-42795%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2023-42795](https://nvd.nist.gov/vuln/detail/CVE-2023-42795) `CVE-2023-45648`|org.apache.tomcat:tomcat-coyote|MEDIUM|5.3|2023-10-10T09:47:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-45648%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2023-45648](https://nvd.nist.gov/vuln/detail/CVE-2023-45648) `CVE-2024-21733`|org.apache.tomcat:tomcat-coyote|MEDIUM|5.3|2024-01-19T11:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2024-21733%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2024-21733](https://nvd.nist.gov/vuln/detail/CVE-2024-21733) `CVE-2023-42795`|org.apache.tomcat:tomcat-util|MEDIUM|5.3|2023-10-10T08:59:00|9.0.22|9.0.81| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2023-42795%3AMaven-org.apache.tomcat%3Atomcat-util-9.0.22/vulnerabilityDetailsGql)|[CVE-2023-42795](https://nvd.nist.gov/vuln/detail/CVE-2023-42795) `CVE-2020-2934`|mysql:mysql-connector-java|MEDIUM|5.0|2020-04-15T14:15:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-2934%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2020-2934](https://nvd.nist.gov/vuln/detail/CVE-2020-2934) `CVE-2022-2764`|io.undertow:undertow-core|MEDIUM|4.9|2022-09-01T10:13:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2022-2764%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2022-2764](https://nvd.nist.gov/vuln/detail/CVE-2022-2764) `CVE-2021-20220`|io.undertow:undertow-core|MEDIUM|4.8|2021-02-23T18:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-20220%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2021-20220](https://nvd.nist.gov/vuln/detail/CVE-2021-20220) `CVE-2020-10687`|io.undertow:undertow-core|MEDIUM|4.8|2020-09-23T13:15:00|2.0.9.Final|2.3.16.SP1-redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-10687%3AMaven-io.undertow%3Aundertow-core-2.0.9.Final/vulnerabilityDetailsGql)|[CVE-2020-10687](https://nvd.nist.gov/vuln/detail/CVE-2020-10687) `CVE-2019-17569`|org.apache.tomcat:tomcat-coyote|MEDIUM|4.8|2020-02-24T22:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2019-17569%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2019-17569](https://nvd.nist.gov/vuln/detail/CVE-2019-17569) `CVE-2020-1935`|org.apache.tomcat:tomcat-coyote|MEDIUM|4.8|2020-02-24T22:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-1935%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-1935](https://nvd.nist.gov/vuln/detail/CVE-2020-1935) `CVE-2020-2875`|mysql:mysql-connector-java|MEDIUM|4.7|2020-04-15T14:15:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-2875%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2020-2875](https://nvd.nist.gov/vuln/detail/CVE-2020-2875) `CVE-2020-13943`|org.apache.tomcat:tomcat-coyote|MEDIUM|4.3|2020-10-12T14:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-13943%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2020-13943](https://nvd.nist.gov/vuln/detail/CVE-2020-13943) `CVE-2021-43980`|org.apache.tomcat:tomcat-coyote|LOW|3.7|2022-09-28T14:15:00|9.0.22|9.0.90| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2021-43980%3AMaven-org.apache.tomcat%3Atomcat-coyote-9.0.22/vulnerabilityDetailsGql)|[CVE-2021-43980](https://nvd.nist.gov/vuln/detail/CVE-2021-43980) `CVE-2017-3589`|mysql:mysql-connector-java|LOW|3.3|2017-04-24T19:59:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2017-3589%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2017-3589](https://nvd.nist.gov/vuln/detail/CVE-2017-3589) `CVE-2020-2933`|mysql:mysql-connector-java|LOW|2.2|2020-04-15T14:15:00|5.1.26|8.0.16.redhat-00001| [Vulnerability Link](https://sca.scacheckmarx.com/#/projects/5136da46-f859-44e8-b3a4-03b35565956a/reports/54c09b48-5bef-4a14-ac69-32b3d3726b48/vulnerabilities/CVE-2020-2933%3AMaven-mysql%3Amysql-connector-java-5.1.26/vulnerabilityDetailsGql)|[CVE-2020-2933](https://nvd.nist.gov/vuln/detail/CVE-2020-2933)
SamHeadrickCx commented 1 month ago

Logo Checkmarx One – Scan Summary & Details1c4b283a-4d0c-4959-a32a-859d9f55bd88

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 43 Attack Vector
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42 Attack Vector
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 43 Attack Vector
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42 Attack Vector
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 43 Attack Vector

Fixed Issues

Severity Issue Source File / Package
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 37
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 38
HIGH SQL_Injection /src/main/webapp/changeCardDetails.jsp: 39
HIGH SQL_Injection /src/main/webapp/ForgotPassword.jsp: 42
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/webapp/admin/adminlogin.jsp: 19
HIGH Second_Order_SQL_Injection /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 52
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
HIGH Stored_XSS /src/main/webapp/ForgotPassword.jsp: 42
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 39
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 38
MEDIUM CSRF /src/main/webapp/changeCardDetails.jsp: 37