Attacker Value
Moderate
(1 user assessed)
Exploitability
Low
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
3

CVE-2015-9251

Disclosure Date: January 18, 2018
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
Collection
Techniques
Validation
Validated
Initial Access
Techniques
Validation
Validated

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • jquery,
  • oracle

Products

  • agile product lifecycle management for process 6.2.0.0,
  • agile product lifecycle management for process 6.2.1.0,
  • agile product lifecycle management for process 6.2.2.0,
  • agile product lifecycle management for process 6.2.3.0,
  • agile product lifecycle management for process 6.2.3.1,
  • banking platform 2.6.0,
  • banking platform 2.6.1,
  • banking platform 2.6.2,
  • business process management suite 11.1.1.9.0,
  • business process management suite 12.1.3.0.0,
  • business process management suite 12.2.1.3.0,
  • communications converged application server,
  • communications interactive session recorder 6.0,
  • communications interactive session recorder 6.1,
  • communications interactive session recorder 6.2,
  • communications services gatekeeper,
  • communications webrtc session controller,
  • endeca information discovery studio 3.1.0,
  • endeca information discovery studio 3.2.0,
  • enterprise manager ops center 12.2.2,
  • enterprise manager ops center 12.3.3,
  • enterprise operations monitor 3.4,
  • enterprise operations monitor 4.0,
  • financial services analytical applications infrastructure,
  • financial services asset liability management,
  • financial services data integration hub,
  • financial services funds transfer pricing,
  • financial services hedge management and ifrs valuations,
  • financial services liquidity risk management,
  • financial services loan loss forecasting and provisioning,
  • financial services market risk measurement and management 8.0.5,
  • financial services market risk measurement and management 8.0.6,
  • financial services profitability management,
  • financial services reconciliation framework 8.0.5,
  • financial services reconciliation framework 8.0.6,
  • fusion middleware mapviewer 12.2.1.3.0,
  • healthcare foundation 7.1,
  • healthcare foundation 7.2,
  • healthcare translational research 3.1.0,
  • hospitality cruise fleet management 9.0.11,
  • hospitality guest access 4.2.0,
  • hospitality guest access 4.2.1,
  • hospitality materials control 18.1,
  • hospitality reporting and analytics 9.1.0,
  • insurance insbridge rating and underwriting 5.2,
  • insurance insbridge rating and underwriting 5.4,
  • insurance insbridge rating and underwriting 5.5,
  • jd edwards enterpriseone tools 9.2,
  • jdeveloper 11.1.1.9.0,
  • jdeveloper 12.1.3.0.0,
  • jdeveloper 12.2.1.3.0,
  • jquery,
  • oss support tools 19.1,
  • peoplesoft enterprise peopletools 8.55,
  • peoplesoft enterprise peopletools 8.56,
  • peoplesoft enterprise peopletools 8.57,
  • primavera gateway 15.2,
  • primavera gateway 16.2,
  • primavera gateway 17.12,
  • primavera unifier,
  • primavera unifier 16.1,
  • primavera unifier 16.2,
  • primavera unifier 18.8,
  • real-time scheduler 2.3.0,
  • retail allocation 15.0.2,
  • retail customer insights 15.0,
  • retail customer insights 16.0,
  • retail invoice matching 15.0,
  • retail sales audit 15.0,
  • retail workforce management software 1.60.9,
  • retail workforce management software 1.64.0,
  • service bus 12.1.3.0.0,
  • service bus 12.2.1.3.0,
  • siebel ui framework 18.10,
  • siebel ui framework 18.11,
  • utilities framework,
  • utilities mobile workforce management 2.3.0,
  • webcenter sites 11.1.1.8.0,
  • weblogic server 12.1.3.0,
  • weblogic server 12.2.1.3

References

Advisory

Additional Info

Technical Analysis