jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2018-01-18 23:29
Updated : 2024-11-21 02:40
NVD link : CVE-2015-9251
Mitre link : CVE-2015-9251
CVE.ORG link : CVE-2015-9251
JSON object : View
Products Affected
                oracle
- hospitality_materials_control
- primavera_unifier
- webcenter_sites
- healthcare_translational_research
- communications_interactive_session_recorder
- insurance_insbridge_rating_and_underwriting
- financial_services_funds_transfer_pricing
- jdeveloper
- communications_converged_application_server
- communications_webrtc_session_controller
- financial_services_loan_loss_forecasting_and_provisioning
- utilities_mobile_workforce_management
- financial_services_liquidity_risk_management
- communications_services_gatekeeper
- jd_edwards_enterpriseone_tools
- retail_allocation
- financial_services_hedge_management_and_ifrs_valuations
- retail_invoice_matching
- primavera_gateway
- service_bus
- agile_product_lifecycle_management_for_process
- banking_platform
- financial_services_analytical_applications_infrastructure
- hospitality_cruise_fleet_management
- real-time_scheduler
- financial_services_data_integration_hub
- fusion_middleware_mapviewer
- financial_services_profitability_management
- oss_support_tools
- enterprise_manager_ops_center
- retail_sales_audit
- business_process_management_suite
- hospitality_guest_access
- utilities_framework
- financial_services_market_risk_measurement_and_management
- financial_services_reconciliation_framework
- endeca_information_discovery_studio
- peoplesoft_enterprise_peopletools
- hospitality_reporting_and_analytics
- siebel_ui_framework
- enterprise_operations_monitor
- financial_services_asset_liability_management
- retail_customer_insights
- healthcare_foundation
- weblogic_server
- retail_workforce_management_software
jquery
- jquery
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
