← Back

CVE-2015-9251

nvd nist
Published: Jan 18, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Affected (81)

Products: Jquery: Jquery · Oracle: Agile Product Lifecycle Management For Process, Banking Platform, Business Process Management Suite, Communications Converged Application Server, Communications Interactive Session Recorder, Communications Services Gatekeeper, Communications Webrtc Session Controller, Endeca Information Discovery Studio, Enterprise Manager Ops Center, Enterprise Operations Monitor, Financial Services Analytical Applications Infrastructure, Financial Services Asset Liability Management, Financial Services Data Integration Hub, Financial Services Funds Transfer Pricing, Financial Services Hedge Management And Ifrs Valuations, Financial Services Liquidity Risk Management, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Market Risk Measurement And Management, Financial Services Profitability Management, Financial Services Reconciliation Framework, Fusion Middleware Mapviewer, Healthcare Foundation, Healthcare Translational Research, Hospitality Cruise Fleet Management, Hospitality Guest Access, Hospitality Materials Control, Hospitality Reporting And Analytics, Insurance Insbridge Rating And Underwriting, Jd Edwards Enterpriseone Tools, Jdeveloper, Oss Support Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Real Time Scheduler, Retail Allocation, Retail Customer Insights, Retail Invoice Matching, Retail Sales Audit, Retail Workforce Management Software, Service Bus, Siebel Ui Framework, Utilities Framework, Utilities Mobile Workforce Management, Webcenter Sites, Weblogic Server
1 product
Jquery
46 products
Banking Platform
Business Process Management Suite
Enterprise Manager Ops Center
Enterprise Operations Monitor
Fusion Middleware Mapviewer
Healthcare Foundation
Healthcare Translational Research
Hospitality Guest Access
Hospitality Materials Control
Jd Edwards Enterpriseone Tools
Jdeveloper
Oss Support Tools
Peoplesoft Enterprise Peopletools
Primavera Gateway
Primavera Unifier
Real Time Scheduler
Retail Allocation
Retail Customer Insights
Retail Invoice Matching
Retail Sales Audit
Service Bus
Siebel Ui Framework
Utilities Framework
Webcenter Sites
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.0.0
Configuration B
80 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 6.2.0.0
Version 6.2.1.0
Version 6.2.2.0
Version 6.2.3.0
Version 6.2.3.1
Oracle
Version 2.6.0
Version 2.6.1
Version 2.6.2
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Before 7.0.0.1
Oracle
Version 6.0
Version 6.1
Version 6.2
Before 6.1.0.4.0
Before 7.2
Oracle
Version 3.1.0
Version 3.2.0
Oracle
Version 12.2.2
Version 12.3.3
Oracle
Version 3.4
Version 4.0
Oracle
From 7.3.3 to 7.3.5
From 8.0.0 to 8.0.7
From 8.0.4 to 8.0.7
From 8.0.5 to 8.0.7
From 8.0.4 to 8.0.7
From 8.0.4 to 8.0.7
From 8.0.2 to 8.0.6
From 8.0.2 to 8.0.7
Oracle
Version 8.0.5
Version 8.0.6
From 8.0.4 to 8.0.6
Oracle
Version 8.0.5
Version 8.0.6
Version 12.2.1.3.0
Oracle
Version 7.1
Version 7.2
Version 3.1.0
Version 9.0.11
Oracle
Version 4.2.0
Version 4.2.1
Version 18.1
Version 9.1.0
Oracle
Version 5.2
Version 5.4
Version 5.5
Version 9.2
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 19.1
Oracle
Version 8.55
Version 8.56
Version 8.57
Oracle
Version 15.2
Version 16.2
Version 17.12
Oracle
From 17.1 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 2.3.0
Version 15.0.2
Oracle
Version 15.0
Version 16.0
Version 15.0
Version 15.0
Oracle
Version 1.60.9
Version 1.64.0
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
Version 18.10
Version 18.11
From 4.3.0.1 to 4.3.0.4
Version 2.3.0
Version 11.1.1.8.0
Oracle
Version 12.1.3.0
Version 12.2.1.3

References (76)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.