CVE-2015-9251

UnknownEPSS 30.22%

Last modified

CVE-2015-9251 is a vulnerability of currently unknown severity. jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.. EPSS estimates a 30.22% chance of exploitation in the next 30 days.

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Metrics

EPSS Probability
30.22%

98.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JqueryJquery< 3.0.0
OracleAgile Product Lifecycle Management For Process6.2.0.0
OracleAgile Product Lifecycle Management For Process6.2.1.0
OracleAgile Product Lifecycle Management For Process6.2.2.0
OracleAgile Product Lifecycle Management For Process6.2.3.0
OracleAgile Product Lifecycle Management For Process6.2.3.1
OracleBanking Platform2.6.0
OracleBanking Platform2.6.1
OracleBanking Platform2.6.2
OracleBusiness Process Management Suite11.1.1.9.0
OracleBusiness Process Management Suite12.1.3.0.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Interactive Session Recorder6.0
OracleCommunications Interactive Session Recorder6.1
OracleCommunications Interactive Session Recorder6.2
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleCommunications Webrtc Session Controller< 7.2
OracleEndeca Information Discovery Studio3.1.0
OracleEndeca Information Discovery Studio3.2.0
OracleEnterprise Manager Ops Center12.2.2
OracleEnterprise Manager Ops Center12.3.3
OracleEnterprise Operations Monitor3.4
OracleEnterprise Operations Monitor4.0
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3, <= 7.3.5
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.0, <= 8.0.7
OracleFinancial Services Asset Liability Management>= 8.0.4, <= 8.0.7
OracleFinancial Services Data Integration Hub>= 8.0.5, <= 8.0.7
OracleFinancial Services Funds Transfer Pricing>= 8.0.4, <= 8.0.7
OracleFinancial Services Hedge Management And Ifrs Valuations>= 8.0.4, <= 8.0.7
OracleFinancial Services Liquidity Risk Management>= 8.0.2, <= 8.0.6
OracleFinancial Services Loan Loss Forecasting And Provisioning>= 8.0.2, <= 8.0.7
OracleFinancial Services Market Risk Measurement And Management8.0.5
OracleFinancial Services Market Risk Measurement And Management8.0.6
OracleFinancial Services Profitability Management>= 8.0.4, <= 8.0.6
OracleFinancial Services Reconciliation Framework8.0.5
OracleFinancial Services Reconciliation Framework8.0.6
OracleFusion Middleware Mapviewer12.2.1.3.0
OracleHealthcare Foundation7.1
OracleHealthcare Foundation7.2
OracleHealthcare Translational Research3.1.0
OracleHospitality Cruise Fleet Management9.0.11
OracleHospitality Guest Access4.2.0
OracleHospitality Guest Access4.2.1
OracleHospitality Materials Control18.1
OracleHospitality Reporting And Analytics9.1.0
OracleInsurance Insbridge Rating And Underwriting5.2
OracleInsurance Insbridge Rating And Underwriting5.4
OracleInsurance Insbridge Rating And Underwriting5.5
OracleJd Edwards Enterpriseone Tools9.2

Showing 50 of 81 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-9251?
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
How severe is CVE-2015-9251?
Severity scoring for CVE-2015-9251 is pending analysis. The EPSS model estimates a 30.22% probability of exploitation in the next 30 days.
How do I fix CVE-2015-9251?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-9251?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST