Reference Guide
Component name License type
hibernate-envers-5.2.8.Final.jar GNU Lesser General Public License License Path https://
www.gnu.org/licenses/lgpl-2.1.html
hibernate-jpa-2.1-api-1.0.0.Final.jar EPL - v.1.0 and EDL 1.0 EPL 1.0 https://mvnrepository.com/
artifact/org.hibernate.javax.persistence/hibernate-jpa-2.1-api/
1.0.0.Final
hibernate-validator-6.0.7.Final.jar GNU Lesser General Public License https://mvnrepository.com/
artifact/org.hibernate/hibernate-validator/6.0.7.Final
httpclient-4.5.4.jar The Apache Software License, Version 2.0 http://
www.apache.org/licenses/LICENSE-2.0.txt https://
mvnrepository.com/artifact/org.apache.httpcomponents/
httpclient/4.5.4
httpcore-4.4.7.jar The Apache Software License, Version 2.0 http://
www.apache.org/licenses/LICENSE-2.0.txt https://
mvnrepository.com/artifact/org.apache.httpcomponents/
httpcore/4.4.7
jandex-2.0.3.Final.jar LGPL 2.1 http://repository.jboss.org/licenses/lgpl-2.1.txt
javassist-3.20.0-GA.jar Apache 2.0, LGPL 2.1 and MPL 1.1 licenses https://
mvnrepository.com/artifact/org.javassist/javassist/3.20.0-GA
javax.servlet-api-4.0.0.jar CDDL and GPL 2.0 https://mvnrepository.com/artifact/
javax.servlet/javax.servlet-api/4.0.0 the license information is listed
as (CDDL + GPLv2 with classpath exception https://
oss.oracle.com/licenses/CDDL+GPL-1.1)
jboss-logging-3.3.0.Final.jar Apache License, version 2.0 https://mvnrepository.com/artifact/
org.jboss.logging/jboss-logging/3.3.0.Final
jboss-transaction-api_1.2_spec-1.0.1.Final.jar CDDL and GPL 2.0 https://mvnrepository.com/artifact/
org.jboss.spec.javax.transaction/jboss-transaction-api_1.2_spec/
1.0.1.Final Engineering team comment - All legal team’s comments
are not applicable to us as we do not create any custom
communication nor inject any binary code.
jcifs-1.3.17.jar GNU Lesser General Public License, version 2.1 https://
mvnrepository.com/artifact/jcifs/jcifs/1.3.17
jcl-over-slf4j-1.7.25.jar MIT License https://mvnrepository.com/artifact/org.slf4j/jcl-
over-slf4j/1.7.25
joda-time-2.9.9.jar Apache 2.0 https://mvnrepository.com/artifact/joda-time/joda-
time/2.9.9 Vulnerability Details: https://github.com/JodaOrg/
joda-time/issues/461 There multiple CWE-73 and CWE-470 issues
in the Joda-Time-2.9.9.jar The more information regarding these
vulnerabilities can be found at: http://cwe.mitre.org/data/
definitions/73.html http://cwe.mitre.org/data/definitions/
470.html
jsoup-1.11.2.jar The MIT License https://mvnrepository.com/artifact/org.jsoup/
jsoup/1.11.2
jsr305-1.3.9.jar The Apache Software License, Version 2.0 https://
mvnrepository.com/artifact/com.google.code.findbugs/
jsr305/1.3.9
Third party licenses 7