Medium severity5.4NVD Advisory· Published Jun 12, 2019· Updated Jun 17, 2026
CVE-2019-3872
CVE-2019-3872
Description
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
- Range: 7.2.x, 7.1.x
- Range: 7.2.x, 7.1.x
- Red Hat/picketlinkv5Range: as shipped with Jboss Enterprise Application Platform 7.2.x and 7.1.x
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/108732nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.