6.5

CVE-2021-41182

Exploit

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JqueryuiJquery Ui SwPlatformjquery Version < 1.13.0
FedoraprojectFedora Version33
FedoraprojectFedora Version34
FedoraprojectFedora Version35
FedoraprojectFedora Version36
NetappH500s Firmware Version-
   NetappH500s Version-
NetappH700s Firmware Version-
   NetappH700s Version-
NetappH300e Firmware Version-
   NetappH300e Version-
NetappH500e Firmware Version-
   NetappH500e Version-
NetappH700e Firmware Version-
   NetappH700e Version-
NetappH410s Firmware Version-
   NetappH410s Version-
NetappH410c Firmware Version-
   NetappH410c Version-
NetappH300s Firmware Version-
   NetappH300s Version-
DebianDebian Linux Version9.0
DrupalDrupal Version >= 7.0 < 7.86
OracleHospitality Suite8 Version >= 8.11.0 <= 8.14.0
OracleHospitality Suite8 Version8.10.2
OracleMysql Enterprise Monitor Version <= 8.0.29
OraclePrimavera Unifier Version17.7
OraclePrimavera Unifier Version17.8
OraclePrimavera Unifier Version17.9
OraclePrimavera Unifier Version17.10
OraclePrimavera Unifier Version17.11
OraclePrimavera Unifier Version17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
TenableTenable.Sc Version < 5.21.0
OracleAgile Plm Version9.3.6
OracleApplication Express Version < 22.1.1
OracleBanking Platform Version2.9.0
OracleBanking Platform Version2.12.0
OracleHospitality Suite8 Version >= 8.11.0 <= 8.14.0
OracleHospitality Suite8 Version8.10.2
OracleJd Edwards Enterpriseone Tools Version <= 9.2.6.3
OraclePolicy Automation Version >= 12.2.0 <= 12.2.25
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRest Data Services SwEdition- Version < 22.1.1
OracleRest Data Services Version22.1.1 SwEdition-
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.27% 0.956
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.