CVE-2021-35043
19.07.2021, 15:15
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Vendor | Product | Version |
---|---|---|
antisamy_project | antisamy | 𝑥 < 1.6.4 |
oracle | retail_back_office | 14.0 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.0 |
oracle | retail_central_office | 14.1 |
oracle | retail_returns_management | 14.0 |
oracle | retail_returns_management | 14.1 |
oracle | banking_enterprise_default_management | 2.6.2 |
oracle | banking_enterprise_default_management | 2.7.0 |
oracle | banking_enterprise_default_management | 2.7.1 |
oracle | banking_enterprise_default_management | 2.10.0 |
oracle | banking_enterprise_default_management | 2.12.0 |
oracle | banking_enterprise_default_managment | 2.3.0 ≤ 𝑥 ≤ 2.4.0 |
oracle | banking_party_management | 2.7.0 |
oracle | banking_platform | 2.3.0 ≤ 𝑥 ≤ 2.4.1 |
oracle | banking_platform | 2.6.2 |
oracle | banking_platform | 2.7.0 |
oracle | banking_platform | 2.7.1 |
oracle | insurance_policy_administration | 11.0.2 |
oracle | insurance_policy_administration | 11.1.0 |
oracle | insurance_policy_administration | 11.2.8 |
oracle | insurance_policy_administration | 11.3.0 |
oracle | insurance_policy_administration | 11.3.1 |
oracle | middleware_common_libraries_and_tools | 12.2.1.3.0 |
oracle | middleware_common_libraries_and_tools | 12.2.1.4.0 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References