Vulnerability Intelligence Report
CVE-2015-9251
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
No Active Exploit Signals
CVSS Base Score
6.1
MEDIUM
EPSS Probability:30.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| jquery | jquery | all |
| oracle | agile_product_lifecycle_management_for_process | 6.2.0.0, 6.2.1.0, 6.2.2.0, 6.2.3.0, 6.2.3.1 |
| oracle | banking_platform | 2.6.0, 2.6.1, 2.6.2 |
| oracle | business_process_management_suite | 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 |
| oracle | communications_converged_application_server | all |
| oracle | communications_interactive_session_recorder | 6.0, 6.1, 6.2 |
| oracle | communications_services_gatekeeper | all |
| oracle | communications_webrtc_session_controller | all |
| oracle | endeca_information_discovery_studio | 3.1.0, 3.2.0 |
| oracle | enterprise_manager_ops_center | 12.2.2, 12.3.3 |
| oracle | enterprise_operations_monitor | 3.4, 4.0 |
| oracle | financial_services_analytical_applications_infrastructure | all |
| oracle | financial_services_asset_liability_management | all |
| oracle | financial_services_data_integration_hub | all |
| oracle | financial_services_funds_transfer_pricing | all |
| oracle | financial_services_hedge_management_and_ifrs_valuations | all |
| oracle | financial_services_liquidity_risk_management | all |
| oracle | financial_services_loan_loss_forecasting_and_provisioning | all |
| oracle | financial_services_market_risk_measurement_and_management | 8.0.5, 8.0.6 |
| oracle | financial_services_profitability_management | all |
| oracle | financial_services_reconciliation_framework | 8.0.5, 8.0.6 |
| oracle | fusion_middleware_mapviewer | 12.2.1.3.0 |
| oracle | healthcare_foundation | 7.1, 7.2 |
| oracle | healthcare_translational_research | 3.1.0 |
| oracle | hospitality_cruise_fleet_management | 9.0.11 |
| oracle | hospitality_guest_access | 4.2.0, 4.2.1 |
| oracle | hospitality_materials_control | 18.1 |
| oracle | hospitality_reporting_and_analytics | 9.1.0 |
| oracle | insurance_insbridge_rating_and_underwriting | 5.2, 5.4, 5.5 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | jdeveloper | 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 |
| oracle | oss_support_tools | 19.1 |
| oracle | peoplesoft_enterprise_peopletools | 8.55, 8.56, 8.57 |
| oracle | primavera_gateway | 15.2, 16.2, 17.12 |
| oracle | primavera_unifier | 16.1, 16.2, 18.8 |
| oracle | real-time_scheduler | 2.3.0 |
| oracle | retail_allocation | 15.0.2 |
| oracle | retail_customer_insights | 15.0, 16.0 |
| oracle | retail_invoice_matching | 15.0 |
| oracle | retail_sales_audit | 15.0 |
| oracle | retail_workforce_management_software | 1.60.9, 1.64.0 |
| oracle | service_bus | 12.1.3.0.0, 12.2.1.3.0 |
| oracle | siebel_ui_framework | 18.10, 18.11 |
| oracle | utilities_framework | all |
| oracle | utilities_mobile_workforce_management | 2.3.0 |
| oracle | webcenter_sites | 11.1.1.8.0 |
| oracle | weblogic_server | 12.1.3.0, 12.2.1.3 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
30.224%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2018-01-18T00:00:00 |
| Published | 2018-01-18T23:00:00 |
| Patch Date | 2018-01-18 |
| Last Updated | 2024-08-06T08:43:41 |
Community Chatter & Buzz