CVE-2016-7103
15.03.2017, 16:59
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
| Vendor | Product | Version |
|---|---|---|
| jqueryui | jquery_ui | 1.10.0 ≤ 𝑥 ≤ 1.11.4 |
| oracle | application_express | 𝑥 < 19.1 |
| oracle | business_intelligence | 12.2.1.3.0 |
| oracle | business_intelligence | 12.2.1.4.0 |
| oracle | hospitality_cruise_fleet_management | 9.0.11 |
| oracle | oss_support_tools | 𝑥 < 2.12.42 |
| oracle | oss_support_tools | 2.12.42 |
| oracle | primavera_unifier | 16.0 ≤ 𝑥 ≤ 16.2 |
| oracle | primavera_unifier | 17.0 ≤ 𝑥 ≤ 17.12.4 |
| oracle | primavera_unifier | 18.0 ≤ 𝑥 ≤ 18.8.4 |
| oracle | siebel_ui_framework | 𝑥 ≤ 21.2 |
| oracle | weblogic_server | 10.3.6.0.0 |
| oracle | weblogic_server | 12.1.3.0.0 |
| oracle | weblogic_server | 12.2.1.3.0 |
| netapp | snapcenter | - |
| redhat | openstack | 7.0 |
| juniper | junos | 21.2 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jqueryui |
|
References