CVE-2015-9251
medium · 6.1jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
6.1
CVSS
29.7%
EPSS (exploit prob.)
98th
EPSS percentile
2018-01-18
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jquery | jquery | < 3.0.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.0.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.1.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.2.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.3.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.3.1 |
| oracle | banking_platform | 2.6.0 |
| oracle | banking_platform | 2.6.1 |
| oracle | banking_platform | 2.6.2 |
| oracle | business_process_management_suite | 11.1.1.9.0 |
| oracle | business_process_management_suite | 12.1.3.0.0 |
| oracle | business_process_management_suite | 12.2.1.3.0 |
| oracle | communications_converged_application_server | < 7.0.0.1 |
| oracle | communications_interactive_session_recorder | 6.0 |
| oracle | communications_interactive_session_recorder | 6.1 |
| oracle | communications_interactive_session_recorder | 6.2 |
| oracle | communications_services_gatekeeper | < 6.1.0.4.0 |
| oracle | communications_webrtc_session_controller | < 7.2 |
| oracle | endeca_information_discovery_studio | 3.1.0 |
| oracle | endeca_information_discovery_studio | 3.2.0 |
| oracle | enterprise_manager_ops_center | 12.2.2 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | enterprise_operations_monitor | 3.4 |
| oracle | enterprise_operations_monitor | 4.0 |
| oracle | financial_services_analytical_applications_infrastructure | >= 7.3.3, <= 7.3.5 |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.0.0, <= 8.0.7 |
| oracle | financial_services_asset_liability_management | >= 8.0.4, <= 8.0.7 |
| oracle | financial_services_data_integration_hub | >= 8.0.5, <= 8.0.7 |
| oracle | financial_services_funds_transfer_pricing | >= 8.0.4, <= 8.0.7 |
| oracle | financial_services_hedge_management_and_ifrs_valuations | >= 8.0.4, <= 8.0.7 |
| oracle | financial_services_liquidity_risk_management | >= 8.0.2, <= 8.0.6 |
| oracle | financial_services_loan_loss_forecasting_and_provisioning | >= 8.0.2, <= 8.0.7 |
| oracle | financial_services_market_risk_measurement_and_management | 8.0.5 |
| oracle | financial_services_market_risk_measurement_and_management | 8.0.6 |
| oracle | financial_services_profitability_management | >= 8.0.4, <= 8.0.6 |
| oracle | financial_services_reconciliation_framework | 8.0.5 |
| oracle | financial_services_reconciliation_framework | 8.0.6 |
| oracle | fusion_middleware_mapviewer | 12.2.1.3.0 |
| oracle | healthcare_foundation | 7.1 |
| oracle | healthcare_foundation | 7.2 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
- http://seclists.org/fulldisclosure/2019/May/10
- http://seclists.org/fulldisclosure/2019/May/11
- http://seclists.org/fulldisclosure/2019/May/13
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/105658
- https://access.redhat.com/errata/RHSA-2020:0481
- https://access.redhat.com/errata/RHSA-2020:0729
- https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc
- https://github.com/jquery/jquery/issues/2432
- https://github.com/jquery/jquery/pull/2588
- https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2
- https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
- https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-9251