6.1
CVE-2019-11358
- EPSS 2.4%
- Published 20.04.2019 00:29:00
- Last modified 21.11.2024 04:20:56
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Data is provided by the National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version8.0
Debian ≫ Debian Linux Version9.0
Debian ≫ Debian Linux Version10.0
Backdropcms ≫ Backdrop Version >= 1.11.0 < 1.11.9
Backdropcms ≫ Backdrop Version >= 1.12.0 < 1.12.6
Fedoraproject ≫ Fedora Version28
Fedoraproject ≫ Fedora Version29
Fedoraproject ≫ Fedora Version30
Opensuse ≫ Backports Sle Version15.0 Updatesp1
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snapcenter Version-
Redhat ≫ Cloudforms Version4.7
Redhat ≫ Virtualization Manager Version4.3
Oracle ≫ Agile Product Lifecycle Management For Process Version6.1
Oracle ≫ Agile Product Lifecycle Management For Process Version6.2.0.0
Oracle ≫ Agile Product Lifecycle Management For Process Version6.2.1.0
Oracle ≫ Agile Product Lifecycle Management For Process Version6.2.2.0
Oracle ≫ Agile Product Lifecycle Management For Process Version6.2.3.0
Oracle ≫ Application Express Version < 19.1
Oracle ≫ Application Service Level Management Version13.2.0.0
Oracle ≫ Application Service Level Management Version13.3.0.0
Oracle ≫ Application Testing Suite Version12.5.0.3
Oracle ≫ Application Testing Suite Version13.1.0.1
Oracle ≫ Application Testing Suite Version13.2
Oracle ≫ Application Testing Suite Version13.2.0.1
Oracle ≫ Application Testing Suite Version13.3
Oracle ≫ Application Testing Suite Version13.3.0.1
Oracle ≫ Banking Digital Experience Version18.1
Oracle ≫ Banking Digital Experience Version18.2
Oracle ≫ Banking Digital Experience Version18.3
Oracle ≫ Banking Digital Experience Version19.1
Oracle ≫ Banking Digital Experience Version19.2
Oracle ≫ Banking Digital Experience Version20.1
Oracle ≫ Banking Enterprise Collections Version >= 2.7.0 <= 2.8.0
Oracle ≫ Banking Platform Version >= 2.4.0 <= 2.10.0
Oracle ≫ Bi Publisher Version5.5.0.0.0
Oracle ≫ Bi Publisher Version12.2.1.3.0
Oracle ≫ Bi Publisher Version12.2.1.4.0
Oracle ≫ Big Data Discovery Version1.6
Oracle ≫ Business Process Management Suite Version12.2.1.3.0
Oracle ≫ Business Process Management Suite Version12.2.1.4.0
Oracle ≫ Communications Analytics Version12.1.1
Oracle ≫ Communications Application Session Controller Version3.8m0
Oracle ≫ Communications Billing And Revenue Management Version7.5
Oracle ≫ Communications Billing And Revenue Management Version7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version12.0
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Diameter Signaling Router Version8.0.0
Oracle ≫ Communications Diameter Signaling Router Version8.1
Oracle ≫ Communications Diameter Signaling Router Version8.2
Oracle ≫ Communications Diameter Signaling Router Version8.2.1
Oracle ≫ Communications Eagle Application Processor Version >= 16.1.0 <= 16.4.0
Oracle ≫ Communications Element Manager Version8.1.1
Oracle ≫ Communications Element Manager Version8.2.0
Oracle ≫ Communications Element Manager Version8.2.1
Oracle ≫ Communications Interactive Session Recorder Version >= 6.0 <= 6.4
Oracle ≫ Communications Operations Monitor Version >= 4.1 <= 4.3
Oracle ≫ Communications Operations Monitor Version3.4
Oracle ≫ Communications Operations Monitor Version4.0
Oracle ≫ Communications Operations Monitor Version4.1.0
Oracle ≫ Communications Services Gatekeeper Version7.0
Oracle ≫ Communications Session Report Manager Version8.1.1
Oracle ≫ Communications Session Report Manager Version8.2.0
Oracle ≫ Communications Session Report Manager Version8.2.1
Oracle ≫ Communications Session Route Manager Version8.1.1
Oracle ≫ Communications Session Route Manager Version8.2.0
Oracle ≫ Communications Session Route Manager Version8.2.1
Oracle ≫ Communications Unified Inventory Management Version7.3
Oracle ≫ Communications Unified Inventory Management Version7.4.0
Oracle ≫ Communications Webrtc Session Controller Version7.2
Oracle ≫ Diagnostic Assistant Version2.12.36
Oracle ≫ Enterprise Manager Ops Center Version12.3.3
Oracle ≫ Enterprise Manager Ops Center Version12.4.0
Oracle ≫ Enterprise Manager Ops Center Version12.4.0.0
Oracle ≫ Enterprise Session Border Controller Version8.4
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 7.3.3 <= 7.3.5
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.2 <= 8.1.0
Oracle ≫ Financial Services Analytical Applications Reconciliation Framework Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Asset Liability Management Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Asset Liability Management Version8.1.0
Oracle ≫ Financial Services Balance Sheet Planning Version8.0.8
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version8.1.0
Oracle ≫ Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Data Foundation Version >= 8.0.4 <= 8.0.8
Oracle ≫ Financial Services Data Governance For Us Regulatory Reporting Version >= 8.0.6 <= 8.0.9
Oracle ≫ Financial Services Data Integration Hub Version >= 8.0.5 <= 8.0.7
Oracle ≫ Financial Services Data Integration Hub Version8.1.0
Oracle ≫ Financial Services Funds Transfer Pricing Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Funds Transfer Pricing Version8.1.0
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version8.1.0
Oracle ≫ Financial Services Institutional Performance Analytics Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Institutional Performance Analytics Version8.1.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.0.1.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.2
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.4.0.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.5.0.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.6
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version >= 8.0.2 <= 8.0.7
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version8.1.0
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.5
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.6
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.8
Oracle ≫ Financial Services Price Creation And Discovery Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Profitability Management Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Profitability Management Version8.1.0
Oracle ≫ Financial Services Regulatory Reporting For Us Federal Reserve Version >= 8.0.4 <= 8.0.7
Oracle ≫ Financial Services Retail Customer Analytics Version >= 8.0.4 <= 8.0.6
Oracle ≫ Financial Services Retail Performance Analytics Version8.0.6
Oracle ≫ Financial Services Retail Performance Analytics Version8.0.7
Oracle ≫ Financial Services Revenue Management And Billing Version2.4.0.0
Oracle ≫ Financial Services Revenue Management And Billing Version2.4.0.1
Oracle ≫ Fusion Middleware Mapviewer Version12.2.1.3.0
Oracle ≫ Healthcare Foundation Version7.1.1
Oracle ≫ Healthcare Foundation Version7.2.0
Oracle ≫ Healthcare Foundation Version7.2.2
Oracle ≫ Healthcare Foundation Version7.3.0
Oracle ≫ Healthcare Translational Research Version3.1.0
Oracle ≫ Healthcare Translational Research Version3.2.1
Oracle ≫ Healthcare Translational Research Version3.3.1
Oracle ≫ Healthcare Translational Research Version3.3.2
Oracle ≫ Healthcare Translational Research Version3.4.0
Oracle ≫ Hospitality Guest Access Version4.2.0
Oracle ≫ Hospitality Guest Access Version4.2.1
Oracle ≫ Hospitality Materials Control Version18.1
Oracle ≫ Hospitality Simphony Version >= 19.1.0 <= 19.1.2
Oracle ≫ Hospitality Simphony Version18.1
Oracle ≫ Hospitality Simphony Version18.2
Oracle ≫ Identity Manager Version12.2.1.3.0
Oracle ≫ Insurance Accounting Analyzer Version8.0.9
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.0.8
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.1.0
Oracle ≫ Insurance Data Foundation Version >= 8.0.4 <= 8.0.7
Oracle ≫ Insurance Ifrs 17 Analyzer Version8.0.6
Oracle ≫ Insurance Ifrs 17 Analyzer Version8.0.7
Oracle ≫ Insurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version5.6.1.0
Oracle ≫ Insurance Performance Insight Version8.0.7
Oracle ≫ Jd Edwards Enterpriseone Tools Version9.2
Oracle ≫ Jdeveloper Version11.1.1.9.0
Oracle ≫ Jdeveloper Version12.2.1.3.0
Oracle ≫ Jdeveloper Version12.2.1.4.0
Oracle ≫ Jdeveloper And Adf Version11.1.1.9.0
Oracle ≫ Jdeveloper And Adf Version12.1.3.0.0
Oracle ≫ Jdeveloper And Adf Version12.2.1.3.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.55
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.57
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.15
Oracle ≫ Policy Automation Version10.4.7
Oracle ≫ Policy Automation Version12.1.0
Oracle ≫ Policy Automation Version12.1.1
Oracle ≫ Policy Automation Connector For Siebel Version10.4.6
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.15
Oracle ≫ Primavera Gateway Version >= 16.2.0 <= 16.2.11
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.7
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.9
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.4
Oracle ≫ Primavera Gateway Version15.2.18
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version16.1
Oracle ≫ Primavera Unifier Version16.2
Oracle ≫ Primavera Unifier Version18.8
Oracle ≫ Real-time Scheduler Version >= 2.3.0.1 <= 2.3.0.3
Oracle ≫ Rest Data Services Version11.2.0.4 SwEdition-
Oracle ≫ Rest Data Services Version12.1.0.2 SwEdition-
Oracle ≫ Rest Data Services Version12.2.0.1 SwEdition-
Oracle ≫ Rest Data Services Version18c SwEdition-
Oracle ≫ Rest Data Services Version19c SwEdition-
Oracle ≫ Retail Back Office Version14.0
Oracle ≫ Retail Back Office Version14.1
Oracle ≫ Retail Central Office Version14.0
Oracle ≫ Retail Central Office Version14.1
Oracle ≫ Retail Customer Insights Version15.0
Oracle ≫ Retail Customer Insights Version16.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version18.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version19.0
Oracle ≫ Retail Point-of-service Version14.0
Oracle ≫ Retail Point-of-service Version14.1
Oracle ≫ Retail Returns Management Version14.0
Oracle ≫ Retail Returns Management Version14.1
Oracle ≫ Service Bus Version11.1.1.9.0
Oracle ≫ Service Bus Version12.1.3.0.0
Oracle ≫ Service Bus Version12.2.1.3.0
Oracle ≫ Siebel Mobile Applications Version <= 19.8
Oracle ≫ Siebel Ui Framework Version20.8
Oracle ≫ Storagetek Tape Analytics Sw Tool Version2.3.0
Oracle ≫ System Utilities Version19.1
Oracle ≫ Tape Library Acsls Version8.5
Oracle ≫ Tape Library Acsls Version8.5.1
Oracle ≫ Transportation Management Version1.4.3
Oracle ≫ Utilities Mobile Workforce Management Version >= 2.3.0.1 <= 2.3.0.3
Oracle ≫ Webcenter Sites Version12.2.1.3.0
Oracle ≫ Weblogic Server Version10.3.6.0.0
Oracle ≫ Weblogic Server Version12.1.3.0.0
Oracle ≫ Weblogic Server Version12.2.1.3.0
Oracle ≫ Weblogic Server Version12.2.1.4.0
Oracle ≫ Weblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.4% | 0.845 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.