6.1

CVE-2016-7103

Exploit
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jqueryui ≫ Jquery Ui Version >= 1.10.0 <= 1.11.4
Oracle ≫ Application Express Version < 19.1
Oracle ≫ Business Intelligence Version 12.2.1.3.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.4.0 SwEdition enterprise
Oracle ≫ Oss Support Tools Version < 2.12.42
Oracle ≫ Oss Support Tools Version 2.12.42
Oracle ≫ Primavera Unifier Version >= 16.0 <= 16.2
Oracle ≫ Primavera Unifier Version >= 17.0 <= 17.12.4
Oracle ≫ Primavera Unifier Version >= 18.0 <= 18.8.4
Oracle ≫ Siebel Ui Framework Version <= 21.2
Oracle ≫ Weblogic Server Version 10.3.6.0.0
Oracle ≫ Weblogic Server Version 12.1.3.0.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Netapp ≫ Snapcenter Version -
Redhat ≫ Openstack Version 7.0
Redhat ≫ Openstack Version 8
Redhat ≫ Openstack Version 9
Juniper ≫ Junos Version 21.2 Update -
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.58% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://security.netapp.com/advisory/ntap-20190416-0007/
Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
Third Party Advisory
Mailing List
https://www.oracle.com/security-alerts/cpujan2022.html
Third Party Advisory
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
Third Party Advisory
Mailing List
https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
Third Party Advisory
Mailing List
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/01/msg00014.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
Third Party Advisory
Mailing List
https://www.drupal.org/sa-core-2022-002
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
Third Party Advisory
https://www.tenable.com/security/tns-2016-19
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2932.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2933.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0161.html
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/104823
Third Party Advisory
Broken Link
VDB Entry
https://github.com/jquery/api.jqueryui.com/issues/281
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/jquery/jquery-ui/commit/9644e7bae9116edaf8d37c5b38cb32b892f10ff6
Patch
Third Party Advisory
https://jqueryui.com/changelog/1.12.0/
Vendor Advisory
Release Notes
https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2I4UHPIW26FIALH7GGZ3IYUUA53VOOJ/
Third Party Advisory
Mailing List
https://nodesecurity.io/advisories/127
Third Party Advisory