6.9
CVE-2020-11022
- EPSS 22.55%
- Published 29.04.2020 22:15:11
- Last modified 21.11.2024 04:56:36
- Source security-advisories@github.com
- Teams watchlist Login
- Open Login
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Data is provided by the National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version9.0
Fedoraproject ≫ Fedora Version31
Fedoraproject ≫ Fedora Version32
Fedoraproject ≫ Fedora Version33
Oracle ≫ Agile Product Lifecycle Management For Process Version6.2.0.0
Oracle ≫ Application Testing Suite Version13.3.0.1
Oracle ≫ Banking Digital Experience Version18.1
Oracle ≫ Banking Digital Experience Version18.2
Oracle ≫ Banking Digital Experience Version18.3
Oracle ≫ Banking Digital Experience Version19.1
Oracle ≫ Banking Digital Experience Version19.2
Oracle ≫ Banking Digital Experience Version20.1
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Communications Application Session Controller Version3.8m0
Oracle ≫ Communications Billing And Revenue Management Version7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Diameter Signaling Router Idih: Version >= 8.0.0 <= 8.2.2
Oracle ≫ Communications Eagle Application Processor Version >= 16.1.0 <= 16.4.0
Oracle ≫ Communications Services Gatekeeper Version7.0
Oracle ≫ Communications Webrtc Session Controller Version7.2
Oracle ≫ Enterprise Manager Ops Center Version12.4.0.0
Oracle ≫ Enterprise Session Border Controller Version8.4
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.6.0.0 <= 8.1.0.0.0
Oracle ≫ Financial Services Analytical Applications Reconciliation Framework Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Asset Liability Management Version8.0.6
Oracle ≫ Financial Services Asset Liability Management Version8.0.7
Oracle ≫ Financial Services Asset Liability Management Version8.1.0
Oracle ≫ Financial Services Balance Sheet Planning Version8.0.8
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version8.1.0
Oracle ≫ Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Data Foundation Version >= 8.0.6 <= 8.1.0
Oracle ≫ Financial Services Data Governance For Us Regulatory Reporting Version >= 8.0.6 <= 8.0.9
Oracle ≫ Financial Services Data Integration Hub Version8.0.6
Oracle ≫ Financial Services Data Integration Hub Version8.0.7
Oracle ≫ Financial Services Data Integration Hub Version8.1.0
Oracle ≫ Financial Services Funds Transfer Pricing Version8.0.6
Oracle ≫ Financial Services Funds Transfer Pricing Version8.0.7
Oracle ≫ Financial Services Funds Transfer Pricing Version8.1.0
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version8.1.0
Oracle ≫ Financial Services Institutional Performance Analytics Version8.0.6
Oracle ≫ Financial Services Institutional Performance Analytics Version8.0.7
Oracle ≫ Financial Services Institutional Performance Analytics Version8.1.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.6
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version8.1.0
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.6
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.8
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.6
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.7
Oracle ≫ Financial Services Profitability Management Version8.0.6
Oracle ≫ Financial Services Profitability Management Version8.0.7
Oracle ≫ Financial Services Profitability Management Version8.1.0
Oracle ≫ Financial Services Regulatory Reporting For European Banking Authority Version >= 8.0.6 <= 8.1.0
Oracle ≫ Financial Services Regulatory Reporting For Us Federal Reserve Version >= 8.0.6 <= 8.0.9
Oracle ≫ Healthcare Foundation Version7.1.1
Oracle ≫ Healthcare Foundation Version7.2.0
Oracle ≫ Healthcare Foundation Version7.2.1
Oracle ≫ Healthcare Foundation Version7.3.0
Oracle ≫ Hospitality Materials Control Version18.1
Oracle ≫ Hospitality Simphony Version >= 19.1.0 <= 19.1.2
Oracle ≫ Hospitality Simphony Version18.1
Oracle ≫ Hospitality Simphony Version18.2
Oracle ≫ Insurance Accounting Analyzer Version8.0.9
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.0.8
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.1.0
Oracle ≫ Insurance Data Foundation Version >= 8.0.6 <= 8.1.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version5.6.1.0
Oracle ≫ Jdeveloper Version11.1.1.9.0
Oracle ≫ Jdeveloper Version12.2.1.3.0
Oracle ≫ Jdeveloper Version12.2.1.4.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.57
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.20
Oracle ≫ Policy Automation Connector For Siebel Version10.4.6
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.20
Oracle ≫ Retail Back Office Version14.0
Oracle ≫ Retail Back Office Version14.1
Oracle ≫ Retail Customer Management And Segmentation Foundation Version19.0
Oracle ≫ Retail Returns Management Version14.0
Oracle ≫ Retail Returns Management Version14.1
Oracle ≫ Siebel Ui Framework Version20.8
Oracle ≫ Storagetek Acsls Version8.5.1
Oracle ≫ Weblogic Server Version10.3.6.0.0
Oracle ≫ Weblogic Server Version12.1.3.0.0
Oracle ≫ Weblogic Server Version12.2.1.3.0
Oracle ≫ Weblogic Server Version12.2.1.4.0
Oracle ≫ Weblogic Server Version14.1.1.0.0
Netapp ≫ Oncommand Insight Version-
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snap Creator Framework Version-
Netapp ≫ Snapcenter Version-
Netapp ≫ H300s Firmware Version-
Netapp ≫ H500s Firmware Version-
Netapp ≫ H700s Firmware Version-
Netapp ≫ H300e Firmware Version-
Netapp ≫ H500e Firmware Version-
Netapp ≫ H700e Firmware Version-
Netapp ≫ H410s Firmware Version-
Netapp ≫ H410c Firmware Version-
Tenable ≫ Log Correlation Engine Version < 6.0.9
Oracle ≫ Agile Product Supplier Collaboration For Process Version6.2.0.0
Oracle ≫ Banking Digital Experience Version >= 18.1 <= 20.1
Oracle ≫ Communications Application Session Controller Version3.8m0
Oracle ≫ Communications Billing And Revenue Management Version7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Diameter Signaling Router Idih: Version >= 8.0.0 <= 8.2.2
Oracle ≫ Communications Webrtc Session Controller Version7.2
Oracle ≫ Enterprise Manager Ops Center Version12.4.0.0
Oracle ≫ Enterprise Session Border Controller Version8.4
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.6 <= 8.1.0
Oracle ≫ Financial Services Analytical Applications Reconciliation Framework Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Asset Liability Management Version8.0.6
Oracle ≫ Financial Services Asset Liability Management Version8.0.7
Oracle ≫ Financial Services Asset Liability Management Version8.1.0
Oracle ≫ Financial Services Balance Sheet Planning Version8.0.8
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Basel Regulatory Capital Basic Version8.1.0
Oracle ≫ Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Data Foundation Version >= 8.0.6 <= 8.1.0
Oracle ≫ Financial Services Data Governance For Us Regulatory Reporting Version >= 8.0.6 <= 8.0.9
Oracle ≫ Financial Services Data Integration Hub Version8.0.6
Oracle ≫ Financial Services Data Integration Hub Version8.0.7
Oracle ≫ Financial Services Data Integration Hub Version8.1.0
Oracle ≫ Financial Services Funds Transfer Pricing Version8.0.6
Oracle ≫ Financial Services Funds Transfer Pricing Version8.0.7
Oracle ≫ Financial Services Funds Transfer Pricing Version8.1.0
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version8.1.0
Oracle ≫ Financial Services Institutional Performance Analytics Version8.0.6
Oracle ≫ Financial Services Institutional Performance Analytics Version8.0.7
Oracle ≫ Financial Services Institutional Performance Analytics Version8.1.0
Oracle ≫ Financial Services Liquidity Risk Management Version8.0.6
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version >= 8.0.6 <= 8.0.8
Oracle ≫ Financial Services Loan Loss Forecasting And Provisioning Version8.1.0
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.6
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.8
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.6
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.7
Oracle ≫ Financial Services Profitability Management Version8.0.6
Oracle ≫ Financial Services Profitability Management Version8.0.7
Oracle ≫ Financial Services Profitability Management Version8.1.0
Oracle ≫ Financial Services Regulatory Reporting For European Banking Authority Version >= 8.0.6 <= 8.1.0
Oracle ≫ Financial Services Regulatory Reporting For Us Federal Reserve Version >= 8.0.6 <= 8.0.9
Oracle ≫ Healthcare Foundation Version7.1.1
Oracle ≫ Healthcare Foundation Version7.2.0
Oracle ≫ Healthcare Foundation Version7.2.1
Oracle ≫ Healthcare Foundation Version7.3.0
Oracle ≫ Hospitality Materials Control Version18.1
Oracle ≫ Hospitality Simphony Version18.1
Oracle ≫ Hospitality Simphony Version18.2
Oracle ≫ Hospitality Simphony Version19.1.0-19.1.2
Oracle ≫ Insurance Accounting Analyzer Version8.0.9
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.0.8
Oracle ≫ Insurance Allocation Manager For Enterprise Profitability Version8.1.0
Oracle ≫ Insurance Data Foundation Version8.0.6-8.1.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version5.6.1.0
Oracle ≫ Jdeveloper Version11.1.1.9.0
Oracle ≫ Jdeveloper Version12.2.1.3.0
Oracle ≫ Jdeveloper Version12.2.1.4.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.57
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.20
Oracle ≫ Policy Automation Connector For Siebel Version10.4.6
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.20
Oracle ≫ Retail Back Office Version14.0
Oracle ≫ Retail Back Office Version14.1
Oracle ≫ Retail Customer Management And Segmentation Foundation Version19.0
Oracle ≫ Retail Returns Management Version14.0
Oracle ≫ Retail Returns Management Version14.1
Oracle ≫ Siebel Ui Framework Version20.8
Oracle ≫ Weblogic Server Version10.3.6.0.0
Oracle ≫ Weblogic Server Version12.1.3.0.0
Oracle ≫ Weblogic Server Version12.2.1.3.0
Oracle ≫ Weblogic Server Version12.2.1.4.0
Oracle ≫ Weblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 22.55% | 0.956 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
security-advisories@github.com | 6.9 | 1.6 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.