CVE Feed

    Dashboard / CVE / CVE-2015-9251

    CVE-2015-9251

    jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

    Published:Jun 27, 2015
    Last Modified:Nov 21, 2024
    EPS:Jan 18, 2018
    EPSS Score:0.11287
    CVSS Score:6.1

    Affected Products

    Vendor
    Jquery
    Product
    Jquery
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management For Process
    Vendor
    Oracle
    Product
    Banking Platform
    Vendor
    Oracle
    Product
    Business Process Management Suite
    Vendor
    Oracle
    Product
    Communications Converged Application Server
    Vendor
    Oracle
    Product
    Communications Interactive Session Recorder
    Vendor
    Oracle
    Product
    Communications Services Gatekeeper
    Vendor
    Oracle
    Product
    Communications Webrtc Session Controller
    Vendor
    Oracle
    Product
    Endeca Information Discovery Studio
    Vendor
    Oracle
    Product
    Enterprise Manager Ops Center
    Vendor
    Oracle
    Product
    Enterprise Operations Monitor
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Financial Services Asset Liability Management
    Vendor
    Oracle
    Product
    Financial Services Data Integration Hub
    Vendor
    Oracle
    Product
    Financial Services Funds Transfer Pricing
    Vendor
    Oracle
    Product
    Financial Services Hedge Management And Ifrs Valuations
    Vendor
    Oracle
    Product
    Financial Services Liquidity Risk Management
    Vendor
    Oracle
    Product
    Financial Services Loan Loss Forecasting And Provisioning
    Vendor
    Oracle
    Product
    Financial Services Market Risk Measurement And Management
    Vendor
    Oracle
    Product
    Financial Services Profitability Management
    Vendor
    Oracle
    Product
    Financial Services Reconciliation Framework
    Vendor
    Oracle
    Product
    Fusion Middleware Mapviewer
    Vendor
    Oracle
    Product
    Healthcare Foundation
    Vendor
    Oracle
    Product
    Healthcare Translational Research
    Vendor
    Oracle
    Product
    Hospitality Cruise Fleet Management
    Vendor
    Oracle
    Product
    Hospitality Guest Access
    Vendor
    Oracle
    Product
    Hospitality Materials Control
    Vendor
    Oracle
    Product
    Hospitality Reporting And Analytics
    Vendor
    Oracle
    Product
    Insurance Insbridge Rating And Underwriting
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Jdeveloper
    Vendor
    Oracle
    Product
    Oss Support Tools
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Primavera Unifier
    Vendor
    Oracle
    Product
    Real-time Scheduler
    Vendor
    Oracle
    Product
    Retail Allocation
    Vendor
    Oracle
    Product
    Retail Customer Insights
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Sales Audit
    Vendor
    Oracle
    Product
    Retail Workforce Management Software
    Vendor
    Oracle
    Product
    Service Bus
    Vendor
    Oracle
    Product
    Siebel Ui Framework
    Vendor
    Oracle
    Product
    Utilities Framework
    Vendor
    Oracle
    Product
    Utilities Mobile Workforce Management
    Vendor
    Oracle
    Product
    Webcenter Sites
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Fuse

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High