CVE-2015-9251

Aliases:GHSA-rmxg-73gg-4p98
Modified
Published: 18 Jan 2018, 23:00
Last modified:06 Aug 2024, 08:43

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.1 MEDIUM
v3.0 (nvd)
EPSS Score
18.01% MEDIUM
18% probability -9.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jan 2018, 23:00
Published
Vulnerability first disclosed
06 Aug 2024, 08:43
Last Modified
Vulnerability information updated

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS Metrics

  • v3.0MEDIUMScore: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 18.01% Percentile: 95%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • RubyGemsjquery-rails

    < 4.2.0

  • UnknownJQuery

    < 3.0.0

  • org.webjars.npmjquery

    < 1.12.2 | ≥ 1.12.3, < 3.0.0

  • Npmjquery

    < 1.12.2 | ≥ 1.12.3, < 3.0.0

  • NuGetjquery

    < 1.12.2 | ≥ 1.12.3, < 3.0.0

  • oracleagile_product_lifecycle_management_for_process

    6.2.0.0 | 6.2.1.0 | 6.2.2.0 | 6.2.3.0 | 6.2.3.1

  • oraclebanking_platform

    2.6.0 | 2.6.1 | 2.6.2

  • oraclebusiness_process_management_suite

    11.1.1.9.0 | 12.1.3.0.0 | 12.2.1.3.0

  • oraclecommunications_converged_application_server

    < 7.0.0.1

  • oraclecommunications_interactive_session_recorder

    6.0 | 6.1 | 6.2

  • oraclecommunications_services_gatekeeper

    < 6.1.0.4.0

  • oraclecommunications_webrtc_session_controller

    < 7.2

  • oracleendeca_information_discovery_studio

    3.1.0 | 3.2.0

  • oracleenterprise_manager_ops_center

    12.2.2 | 12.3.3

  • oracleenterprise_operations_monitor

    3.4 | 4.0

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 7.3.3, ≤ 7.3.5 | ≥ 8.0.0, ≤ 8.0.7

  • oraclefinancial_services_asset_liability_management

    ≥ 8.0.4, ≤ 8.0.7

  • oraclefinancial_services_data_integration_hub

    ≥ 8.0.5, ≤ 8.0.7

  • oraclefinancial_services_funds_transfer_pricing

    ≥ 8.0.4, ≤ 8.0.7

  • oraclefinancial_services_hedge_management_and_ifrs_valuations

    ≥ 8.0.4, ≤ 8.0.7

  • oraclefinancial_services_liquidity_risk_management

    ≥ 8.0.2, ≤ 8.0.6

  • oraclefinancial_services_loan_loss_forecasting_and_provisioning

    ≥ 8.0.2, ≤ 8.0.7

  • oraclefinancial_services_market_risk_measurement_and_management

    8.0.5 | 8.0.6

  • oraclefinancial_services_profitability_management

    ≥ 8.0.4, ≤ 8.0.6

  • oraclefinancial_services_reconciliation_framework

    8.0.5 | 8.0.6

  • oraclefusion_middleware_mapviewer

    12.2.1.3.0

  • oraclehealthcare_foundation

    7.1 | 7.2

  • oraclehealthcare_translational_research

    3.1.0

  • oraclehospitality_cruise_fleet_management

    9.0.11

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oraclehospitality_materials_control

    18.1

  • oraclehospitality_reporting_and_analytics

    9.1.0

  • oracleinsurance_insbridge_rating_and_underwriting

    5.2 | 5.4 | 5.5

  • oraclejd_edwards_enterpriseone_tools

    9.2

  • oraclejdeveloper

    11.1.1.9.0 | 12.1.3.0.0 | 12.2.1.3.0

  • oracleoss_support_tools

    19.1

  • oraclepeoplesoft_enterprise_peopletools

    8.55 | 8.56 | 8.57

  • oracleprimavera_gateway

    15.2 | 16.2 | 17.12

  • oracleprimavera_unifier

    ≥ 17.1, ≤ 17.12 | 16.1 | 16.2 | 18.8

  • oraclereal-time_scheduler

    2.3.0

  • oracleretail_allocation

    15.0.2

  • oracleretail_customer_insights

    15.0 | 16.0

  • oracleretail_invoice_matching

    15.0

  • oracleretail_sales_audit

    15.0

  • oracleretail_workforce_management_software

    1.60.9 | 1.64.0

  • oracleservice_bus

    12.1.3.0.0 | 12.2.1.3.0

  • oraclesiebel_ui_framework

    18.10 | 18.11

  • oracleutilities_framework

    ≥ 4.3.0.1, ≤ 4.3.0.4

  • oracleutilities_mobile_workforce_management

    2.3.0

  • oraclewebcenter_sites

    11.1.1.8.0

Showing first 50 affected entries in server-rendered view.

References (57)