CVE-2015-9251 - CVE House
Back to Database
Status published Medium CVE-2015-9251

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks...

Vulnerability Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-9251

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jquery, agile product lifecycle management for process, banking platform, business process management suite, communications converged application server, communications interactive session recorder, communications services gatekeeper, communications webrtc session controller, endeca information discovery studio, enterprise manager ops center, enterprise operations monitor, financial services analytical applications infrastructure, financial services asset liability management, financial services data integration hub, financial services funds transfer pricing, financial services hedge management and ifrs valuations, financial services liquidity risk management, financial services loan loss forecasting and provisioning, financial services market risk measurement and management, financial services profitability management, financial services reconciliation framework, fusion middleware mapviewer, healthcare foundation, healthcare translational research, hospitality cruise fleet management, hospitality guest access, hospitality materials control, hospitality reporting and analytics, insurance insbridge rating and underwriting, jd edwards enterpriseone tools, jdeveloper, oss support tools, peoplesoft enterprise peopletools, primavera gateway, primavera unifier, real-time scheduler, retail allocation, retail customer insights, retail invoice matching, retail sales audit, retail workforce management software, service bus, siebel ui framework, utilities framework, utilities mobile workforce management, webcenter sites, weblogic server
Vulnerable Versions:
0, 6.2.0.0, 6.2.1.0, 6.2.2.0, 6.2.3.0, 6.2.3.1, 2.6.0, 2.6.1, 2.6.2, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0, 6.0, 6.1, 6.2, 3.1.0, 3.2.0, 12.2.2, 12.3.3, 3.4, 4.0, 7.3.3, 8.0.0, 8.0.4, 8.0.5, 8.0.2, 8.0.6, 7.1, 7.2, 9.0.11, 4.2.0, 4.2.1, 18.1, 9.1.0, 5.2, 5.4, 5.5, 9.2, 19.1, 8.55, 8.56, 8.57, 15.2, 16.2, 17.12, 17.1, 16.1, 18.8, 2.3.0, 15.0.2, 15.0, 16.0, 1.60.9, 1.64.0, 18.10, 18.11, 4.3.0.1, 11.1.1.8.0, 12.1.3.0, 12.2.1.3

Timeline

Official Publish: January 18th, 2018
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.