383
VMScore

CVE-2019-14862

Published: 02/01/2020 Updated: 07/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

knockoutjs knockout

redhat decision manager 7.0

redhat process automation 7.0

oracle business intelligence 12.2.1.3.0

oracle business intelligence 12.2.1.4.0

oracle business intelligence 5.5.0.0.0

oracle goldengate 12.3.0.1.2

Vendor Advisories

Debian Bug report logs - #943560 node-knockout: CVE-2019-14862 Package: src:node-knockout; Maintainer for src:node-knockout is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Oct 2019 14:33:02 UTC Severity: important Tag ...
Synopsis Important: Red Hat Decision Manager 751 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: Red Hat Process Automation Manager 751 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...