CVE-2015-9251
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Affected (81)
Products: Jquery: Jquery · Oracle: Agile Product Lifecycle Management For Process, Banking Platform, Business Process Management Suite, Communications Converged Application Server, Communications Interactive Session Recorder, Communications Services Gatekeeper, Communications Webrtc Session Controller, Endeca Information Discovery Studio, Enterprise Manager Ops Center, Enterprise Operations Monitor, Financial Services Analytical Applications Infrastructure, Financial Services Asset Liability Management, Financial Services Data Integration Hub, Financial Services Funds Transfer Pricing, Financial Services Hedge Management And Ifrs Valuations, Financial Services Liquidity Risk Management, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Market Risk Measurement And Management, Financial Services Profitability Management, Financial Services Reconciliation Framework, Fusion Middleware Mapviewer, Healthcare Foundation, Healthcare Translational Research, Hospitality Cruise Fleet Management, Hospitality Guest Access, Hospitality Materials Control, Hospitality Reporting And Analytics, Insurance Insbridge Rating And Underwriting, Jd Edwards Enterpriseone Tools, Jdeveloper, Oss Support Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Real Time Scheduler, Retail Allocation, Retail Customer Insights, Retail Invoice Matching, Retail Sales Audit, Retail Workforce Management Software, Service Bus, Siebel Ui Framework, Utilities Framework, Utilities Mobile Workforce Management, Webcenter Sites, Weblogic Server
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.0.0 | |
| Version 2.6.0 | |
| Version 11.1.1.9.0 | |
| Before 7.0.0.1 | |
| Version 6.0 | |
| Before 6.1.0.4.0 | |
| Before 7.2 | |
| Version 3.1.0 | |
| Version 12.2.2 | |
| Version 3.4 | |
| From 7.3.3 to 7.3.5 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.5 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.2 to 8.0.6 | |
| From 8.0.2 to 8.0.7 | |
| Version 8.0.5 | |
| From 8.0.4 to 8.0.6 | |
| Version 8.0.5 | |
| Version 12.2.1.3.0 | |
| Version 7.1 | |
| Version 3.1.0 | |
| Version 9.0.11 | |
| Version 4.2.0 | |
| Version 18.1 | |
| Version 9.1.0 | |
| Version 5.2 | |
| Version 9.2 | |
| Version 11.1.1.9.0 | |
| Version 19.1 | |
| Version 8.55 | |
| Version 15.2 | |
| From 17.1 to 17.12 | |
| Version 2.3.0 | |
| Version 15.0.2 | |
| Version 15.0 | |
| Version 15.0 | |
| Version 15.0 | |
| Version 1.60.9 | |
| Version 12.1.3.0.0 | |
| Version 18.10 | |
| From 4.3.0.1 to 4.3.0.4 | |
| Version 2.3.0 | |
| Version 11.1.1.8.0 | |
| Version 12.1.3.0 |
References (76)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.