CVE-2020-11022
29.04.2020, 22:15
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Vendor | Product | Version |
---|---|---|
jquery | jquery | 1.2 ≤ 𝑥 < 3.5.0 |
drupal | drupal | 7.0 ≤ 𝑥 < 7.70 |
drupal | drupal | 8.7.0 ≤ 𝑥 < 8.7.14 |
drupal | drupal | 8.8.0 ≤ 𝑥 < 8.8.6 |
debian | debian_linux | 9.0 |
oracle | agile_product_lifecycle_management_for_process | 6.2.0.0 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_digital_experience | 18.1 |
oracle | banking_digital_experience | 18.2 |
oracle | banking_digital_experience | 18.3 |
oracle | banking_digital_experience | 19.1 |
oracle | banking_digital_experience | 19.2 |
oracle | banking_digital_experience | 20.1 |
oracle | blockchain_platform | 𝑥 < 21.1.2 |
oracle | communications_application_session_controller | 3.8m0:m0 |
oracle | communications_billing_and_revenue_management | 7.5.0.23.0 |
oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
oracle | communications_diameter_signaling_router_idih\ | 8.0.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_eagle_application_processor | 16.1.0 ≤ 𝑥 ≤ 16.4.0 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_webrtc_session_controller | 7.2 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | enterprise_session_border_controller | 8.4 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6.0.0 ≤ 𝑥 ≤ 8.1.0.0.0 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.1.0 |
oracle | financial_services_asset_liability_management | 8.0.6 |
oracle | financial_services_asset_liability_management | 8.0.7 |
oracle | financial_services_asset_liability_management | 8.1.0 |
oracle | financial_services_balance_sheet_planning | 8.0.8 |
oracle | financial_services_basel_regulatory_capital_basic | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_basel_regulatory_capital_basic | 8.1.0 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.1.0 |
oracle | financial_services_data_foundation | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_data_governance_for_us_regulatory_reporting | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | financial_services_data_integration_hub | 8.0.6 |
oracle | financial_services_data_integration_hub | 8.0.7 |
oracle | financial_services_data_integration_hub | 8.1.0 |
oracle | financial_services_funds_transfer_pricing | 8.0.6 |
oracle | financial_services_funds_transfer_pricing | 8.0.7 |
oracle | financial_services_funds_transfer_pricing | 8.1.0 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.1.0 |
oracle | financial_services_institutional_performance_analytics | 8.0.6 |
oracle | financial_services_institutional_performance_analytics | 8.0.7 |
oracle | financial_services_institutional_performance_analytics | 8.1.0 |
oracle | financial_services_liquidity_risk_management | 8.0.6 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.7 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.1.0 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.1.0 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.6 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_price_creation_and_discovery | 8.0.6 |
oracle | financial_services_price_creation_and_discovery | 8.0.7 |
oracle | financial_services_profitability_management | 8.0.6 |
oracle | financial_services_profitability_management | 8.0.7 |
oracle | financial_services_profitability_management | 8.1.0 |
oracle | financial_services_regulatory_reporting_for_european_banking_authority | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_regulatory_reporting_for_us_federal_reserve | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | healthcare_foundation | 7.1.1 |
oracle | healthcare_foundation | 7.2.0 |
oracle | healthcare_foundation | 7.2.1 |
oracle | healthcare_foundation | 7.3.0 |
oracle | hospitality_materials_control | 18.1 |
oracle | hospitality_simphony | 19.1.0 ≤ 𝑥 ≤ 19.1.2 |
oracle | hospitality_simphony | 18.1 |
oracle | hospitality_simphony | 18.2 |
oracle | insurance_accounting_analyzer | 8.0.9 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.0.8 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.1.0 |
oracle | insurance_data_foundation | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.0.0.0 ≤ 𝑥 ≤ 5.6.0.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.6.1.0 |
oracle | jdeveloper | 11.1.1.9.0 |
oracle | jdeveloper | 12.2.1.3.0 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | peoplesoft_enterprise_peopletools | 8.56 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.20 |
oracle | policy_automation_connector_for_siebel | 10.4.6 |
oracle | policy_automation_for_mobile_devices | 12.2.0 ≤ 𝑥 ≤ 12.2.20 |
oracle | retail_back_office | 14.0 |
oracle | retail_back_office | 14.1 |
oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
oracle | retail_returns_management | 14.0 |
oracle | retail_returns_management | 14.1 |
oracle | siebel_ui_framework | 20.8 |
oracle | storagetek_acsls | 8.5.1 |
oracle | weblogic_server | 10.3.6.0.0 |
oracle | weblogic_server | 12.1.3.0.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
netapp | max_data | - |
netapp | oncommand_insight | - |
netapp | oncommand_system_manager | 3.0 ≤ 𝑥 ≤ 3.1.3 |
netapp | snap_creator_framework | - |
netapp | snapcenter | - |
netapp | h300s_firmware | - |
netapp | h500s_firmware | - |
netapp | h700s_firmware | - |
netapp | h300e_firmware | - |
netapp | h500e_firmware | - |
netapp | h700e_firmware | - |
netapp | h410s_firmware | - |
netapp | h410c_firmware | - |
opensuse | leap | 15.1 |
opensuse | leap | 15.2 |
tenable | log_correlation_engine | 𝑥 < 6.0.9 |
oracle | agile_product_supplier_collaboration_for_process | 6.2.0.0 |
oracle | banking_digital_experience | 18.1 ≤ 𝑥 ≤ 20.1 |
oracle | communications_application_session_controller | 3.8m0:m0 |
oracle | communications_billing_and_revenue_management | 7.5.0.23.0 |
oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
oracle | communications_diameter_signaling_router_idih\ | 8.0.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_webrtc_session_controller | 7.2 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | enterprise_session_border_controller | 8.4 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.1.0 |
oracle | financial_services_asset_liability_management | 8.0.6 |
oracle | financial_services_asset_liability_management | 8.0.7 |
oracle | financial_services_asset_liability_management | 8.1.0 |
oracle | financial_services_balance_sheet_planning | 8.0.8 |
oracle | financial_services_basel_regulatory_capital_basic | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_basel_regulatory_capital_basic | 8.1.0 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.1.0 |
oracle | financial_services_data_foundation | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_data_governance_for_us_regulatory_reporting | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | financial_services_data_integration_hub | 8.0.6 |
oracle | financial_services_data_integration_hub | 8.0.7 |
oracle | financial_services_data_integration_hub | 8.1.0 |
oracle | financial_services_funds_transfer_pricing | 8.0.6 |
oracle | financial_services_funds_transfer_pricing | 8.0.7 |
oracle | financial_services_funds_transfer_pricing | 8.1.0 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.1.0 |
oracle | financial_services_institutional_performance_analytics | 8.0.6 |
oracle | financial_services_institutional_performance_analytics | 8.0.7 |
oracle | financial_services_institutional_performance_analytics | 8.1.0 |
oracle | financial_services_liquidity_risk_management | 8.0.6 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.7 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.1.0 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.0.6 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.1.0 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.6 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_price_creation_and_discovery | 8.0.6 |
oracle | financial_services_price_creation_and_discovery | 8.0.7 |
oracle | financial_services_profitability_management | 8.0.6 |
oracle | financial_services_profitability_management | 8.0.7 |
oracle | financial_services_profitability_management | 8.1.0 |
oracle | financial_services_regulatory_reporting_for_european_banking_authority | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_regulatory_reporting_for_us_federal_reserve | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | healthcare_foundation | 7.1.1 |
oracle | healthcare_foundation | 7.2.0 |
oracle | healthcare_foundation | 7.2.1 |
oracle | healthcare_foundation | 7.3.0 |
oracle | hospitality_materials_control | 18.1 |
oracle | hospitality_simphony | 18.1 |
oracle | hospitality_simphony | 18.2 |
oracle | hospitality_simphony | 19.1.0-19.1.2 |
oracle | insurance_accounting_analyzer | 8.0.9 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.0.8 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.1.0 |
oracle | insurance_data_foundation | 8.0.6-8.1.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.0.0.0 ≤ 𝑥 ≤ 5.6.0.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.6.1.0 |
oracle | jdeveloper | 11.1.1.9.0 |
oracle | jdeveloper | 12.2.1.3.0 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | peoplesoft_enterprise_peopletools | 8.56 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.20 |
oracle | policy_automation_connector_for_siebel | 10.4.6 |
oracle | policy_automation_for_mobile_devices | 12.2.0 ≤ 𝑥 ≤ 12.2.20 |
oracle | retail_back_office | 14.0 |
oracle | retail_back_office | 14.1 |
oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
oracle | retail_returns_management | 14.0 |
oracle | retail_returns_management | 14.1 |
oracle | siebel_ui_framework | 20.8 |
oracle | weblogic_server | 10.3.6.0.0 |
oracle | weblogic_server | 12.1.3.0.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
drupal7 |
| ||||||||||||||||||||||||||
jquery |
|
References