CVE-2020-11022

CVSS V2 Medium 4.3 CVSS V3 Medium 6.1
Description
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Overview
  • CVE ID
  • CVE-2020-11022
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2020-04-29T22:15:11
  • Last Modified Date
  • 2022-07-25T18:15:17
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* 1 OR 1.2 3.5.0
AND
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* 1 OR 7.0 7.70
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* 1 OR 8.7.0 8.7.14
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* 1 OR 8.8.0 8.8.6
AND
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* 1 OR 21.1.2
cpe:2.3:a:oracle:communications_application_session_controller:3.8m0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_diameter_signaling_router_idih\::*:*:*:*:*:*:*:* 1 OR 8.0.0 8.2.2
cpe:2.3:a:oracle:communications_eagle_application_processor:*:*:*:*:*:*:*:* 1 OR 16.1.0 16.4.0
cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_session_border_controller:8.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* 1 OR 8.0.6.0.0 8.1.0.0.0
cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_foundation:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:financial_services_data_governance_for_us_regulatory_reporting:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.9
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_us_federal_reserve:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.9
cpe:2.3:a:oracle:healthcare_foundation:7.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:* 1 OR 19.1.0 19.1.2
cpe:2.3:a:oracle:hospitality_simphony:18.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_simphony:18.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_accounting_analyzer:8.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_data_foundation:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:* 1 OR 5.0.0.0 5.6.0.0
cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* 1 OR 12.2.0 12.2.20
cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:* 1 OR 12.2.0 12.2.20
cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:siebel_ui_framework:20.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:netapp:max_data:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* 1 OR 3.0 3.1.3
cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:tenable:log_correlation_engine:*:*:*:*:*:*:*:* 1 OR 6.0.9
AND
cpe:2.3:a:oracle:agile_product_supplier_collaboration_for_process:6.2.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:* 1 OR 18.1 20.1
cpe:2.3:a:oracle:communications_application_session_controller:3.8m0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:communications_diameter_signaling_router_idih\::*:*:*:*:*:*:*:* 1 OR 8.0.0 8.2.2
cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:enterprise_session_border_controller:8.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_asset_liability_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_foundation:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:financial_services_data_governance_for_us_regulatory_reporting:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.9
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_data_integration_hub:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.8
cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_profitability_management:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_us_federal_reserve:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.0.9
cpe:2.3:a:oracle:healthcare_foundation:7.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_simphony:18.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_simphony:18.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:hospitality_simphony:19.1.0-19.1.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_accounting_analyzer:8.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_data_foundation:8.0.6-8.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:* 1 OR 5.0.0.0 5.6.0.0
cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* 1 OR 12.2.0 12.2.20
cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:* 1 OR 12.2.0 12.2.20
cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:siebel_ui_framework:20.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 4.3
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • CHANGED
  • Confidentiality Impact
  • LOW
  • Availability Impact
  • NONE
  • Base Score
  • 6.1
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 2.8
  • Impact Score
  • 2.7
References
Reference URL Reference Tags
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html Broken Link
http://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.html Exploit Third Party Advisory VDB Entry
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ Release Notes Vendor Advisory
https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77 Patch Third Party Advisory
https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2 Mitigation Third Party Advisory
https://jquery.com/upgrade-guide/3.5/ Mitigation Vendor Advisory
https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133@%3Ccommits.airflow.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/03/msg00033.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W/ Third Party Advisory
https://security.gentoo.org/glsa/202007-03 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200511-0006/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4693 Third Party Advisory
https://www.drupal.org/sa-core-2020-002 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Patch Third Party Advisory
https://www.tenable.com/security/tns-2020-10 Third Party Advisory
https://www.tenable.com/security/tns-2020-11 Third Party Advisory
https://www.tenable.com/security/tns-2021-02 Third Party Advisory
https://www.tenable.com/security/tns-2021-10 Third Party Advisory
History
Created Old Value New Value Data Type Notes
2022-04-20 17:00:03 Added to TrackCVE
2022-12-04 15:58:06 2020-04-29T22:15Z 2020-04-29T22:15:11 CVE Published Date updated
2022-12-04 15:58:06 2022-07-25T18:15:17 CVE Modified Date updated
2022-12-04 15:58:06 Modified Vulnerability Status updated
2022-12-04 15:58:13 References updated