SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-9251

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

MEDIUM 6.1EPSS 29.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 29.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
29.73% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jquery/jquery · oracle/agile product lifecycle management for process · oracle/banking platform · oracle/business process management suite · oracle/communications converged application server · oracle/communications interactive session recorder · oracle/communications services gatekeeper · oracle/communications webrtc session controller · oracle/endeca information discovery studio · oracle/enterprise manager ops center · oracle/enterprise operations monitor · oracle/financial services analytical applications infrastructure · oracle/financial services asset liability management · oracle/financial services data integration hub · oracle/financial services funds transfer pricing · oracle/financial services hedge management and ifrs valuations · oracle/financial services liquidity risk management · oracle/financial services loan loss forecasting and provisioning · oracle/financial services market risk measurement and management · oracle/financial services profitability management · +27 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.