MEDIUM · 6.1

CVE-2015-9251

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Vulnerability Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
JqueryJquery< 3.0.0
OracleAgile Product Lifecycle Management For Process6.2.0.0
OracleBanking Platform2.6.0
OracleBusiness Process Management Suite11.1.1.9.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Interactive Session Recorder6.0
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleCommunications Webrtc Session Controller< 7.2
OracleEndeca Information Discovery Studio3.1.0
OracleEnterprise Manager Ops Center12.2.2
OracleEnterprise Operations Monitor3.4
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3, <= 7.3.5
OracleFinancial Services Asset Liability Management>= 8.0.4, <= 8.0.7
OracleFinancial Services Data Integration Hub>= 8.0.5, <= 8.0.7
OracleFinancial Services Funds Transfer Pricing>= 8.0.4, <= 8.0.7
OracleFinancial Services Hedge Management And Ifrs Valuations>= 8.0.4, <= 8.0.7
OracleFinancial Services Liquidity Risk Management>= 8.0.2, <= 8.0.6
OracleFinancial Services Loan Loss Forecasting And Provisioning>= 8.0.2, <= 8.0.7
OracleFinancial Services Market Risk Measurement And Management8.0.5
OracleFinancial Services Profitability Management>= 8.0.4, <= 8.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-9251?

CVE-2015-9251 is a vulnerability with a CVSS score of 6.1 (MEDIUM). jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

How severe is CVE-2015-9251?

CVE-2015-9251 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-9251?

Check the references section above for vendor advisories and patch information. Affected products include: Jquery Jquery, Oracle Agile Product Lifecycle Management For Process, Oracle Banking Platform, Oracle Business Process Management Suite, Oracle Communications Converged Application Server.