← All CVEs

CVE-2015-9251

medium · 6.1

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

6.1
CVSS
29.7%
EPSS (exploit prob.)
98th
EPSS percentile
2018-01-18
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
jqueryjquery< 3.0.0
oracleagile_product_lifecycle_management_for_process6.2.0.0
oracleagile_product_lifecycle_management_for_process6.2.1.0
oracleagile_product_lifecycle_management_for_process6.2.2.0
oracleagile_product_lifecycle_management_for_process6.2.3.0
oracleagile_product_lifecycle_management_for_process6.2.3.1
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclebusiness_process_management_suite11.1.1.9.0
oraclebusiness_process_management_suite12.1.3.0.0
oraclebusiness_process_management_suite12.2.1.3.0
oraclecommunications_converged_application_server< 7.0.0.1
oraclecommunications_interactive_session_recorder6.0
oraclecommunications_interactive_session_recorder6.1
oraclecommunications_interactive_session_recorder6.2
oraclecommunications_services_gatekeeper< 6.1.0.4.0
oraclecommunications_webrtc_session_controller< 7.2
oracleendeca_information_discovery_studio3.1.0
oracleendeca_information_discovery_studio3.2.0
oracleenterprise_manager_ops_center12.2.2
oracleenterprise_manager_ops_center12.3.3
oracleenterprise_operations_monitor3.4
oracleenterprise_operations_monitor4.0
oraclefinancial_services_analytical_applications_infrastructure>= 7.3.3, <= 7.3.5
oraclefinancial_services_analytical_applications_infrastructure>= 8.0.0, <= 8.0.7
oraclefinancial_services_asset_liability_management>= 8.0.4, <= 8.0.7
oraclefinancial_services_data_integration_hub>= 8.0.5, <= 8.0.7
oraclefinancial_services_funds_transfer_pricing>= 8.0.4, <= 8.0.7
oraclefinancial_services_hedge_management_and_ifrs_valuations>= 8.0.4, <= 8.0.7
oraclefinancial_services_liquidity_risk_management>= 8.0.2, <= 8.0.6
oraclefinancial_services_loan_loss_forecasting_and_provisioning>= 8.0.2, <= 8.0.7
oraclefinancial_services_market_risk_measurement_and_management8.0.5
oraclefinancial_services_market_risk_measurement_and_management8.0.6
oraclefinancial_services_profitability_management>= 8.0.4, <= 8.0.6
oraclefinancial_services_reconciliation_framework8.0.5
oraclefinancial_services_reconciliation_framework8.0.6
oraclefusion_middleware_mapviewer12.2.1.3.0
oraclehealthcare_foundation7.1
oraclehealthcare_foundation7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-9251