Lucene search

K
nvd[email protected]NVD:CVE-2020-11022
HistoryApr 29, 2020 - 10:15 p.m.

CVE-2020-11022

2020-04-2922:15:11
CWE-79
web.nvd.nist.gov
1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

High

0.061 Low

EPSS

Percentile

93.6%

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery’s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Affected configurations

NVD
Node
jqueryjqueryRange1.23.5.0
Node
drupaldrupalRange7.07.70
OR
drupaldrupalRange8.7.08.7.14
OR
drupaldrupalRange8.8.08.8.6
Node
debiandebian_linuxMatch9.0
Node
fedoraprojectfedoraMatch31
OR
fedoraprojectfedoraMatch32
OR
fedoraprojectfedoraMatch33
Node
oracleagile_product_lifecycle_management_for_processMatch6.2.0.0
OR
oracleapplication_testing_suiteMatch13.3.0.1
OR
oraclebanking_digital_experienceMatch18.1
OR
oraclebanking_digital_experienceMatch18.2
OR
oraclebanking_digital_experienceMatch18.3
OR
oraclebanking_digital_experienceMatch19.1
OR
oraclebanking_digital_experienceMatch19.2
OR
oraclebanking_digital_experienceMatch20.1
OR
oracleblockchain_platformRange<21.1.2
OR
oraclecommunications_application_session_controllerMatch3.8m0
OR
oraclecommunications_billing_and_revenue_managementMatch7.5.0.23.0
OR
oraclecommunications_billing_and_revenue_managementMatch12.0.0.3.0
OR
oraclecommunications_diameter_signaling_router_idih\Range8.0.08.2.2
OR
oraclecommunications_eagle_application_processorRange16.1.016.4.0
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_webrtc_session_controllerMatch7.2
OR
oracleenterprise_manager_ops_centerMatch12.4.0.0
OR
oracleenterprise_session_border_controllerMatch8.4
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.6.0.08.1.0.0.0
OR
oraclefinancial_services_analytical_applications_reconciliation_frameworkRange8.0.68.0.8
OR
oraclefinancial_services_analytical_applications_reconciliation_frameworkMatch8.1.0
OR
oraclefinancial_services_asset_liability_managementMatch8.0.6
OR
oraclefinancial_services_asset_liability_managementMatch8.0.7
OR
oraclefinancial_services_asset_liability_managementMatch8.1.0
OR
oraclefinancial_services_balance_sheet_planningMatch8.0.8
OR
oraclefinancial_services_basel_regulatory_capital_basicRange8.0.68.0.8
OR
oraclefinancial_services_basel_regulatory_capital_basicMatch8.1.0
OR
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approachRange8.0.68.0.8
OR
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approachMatch8.1.0
OR
oraclefinancial_services_data_foundationRange8.0.68.1.0
OR
oraclefinancial_services_data_governance_for_us_regulatory_reportingRange8.0.68.0.9
OR
oraclefinancial_services_data_integration_hubMatch8.0.6
OR
oraclefinancial_services_data_integration_hubMatch8.0.7
OR
oraclefinancial_services_data_integration_hubMatch8.1.0
OR
oraclefinancial_services_funds_transfer_pricingMatch8.0.6
OR
oraclefinancial_services_funds_transfer_pricingMatch8.0.7
OR
oraclefinancial_services_funds_transfer_pricingMatch8.1.0
OR
oraclefinancial_services_hedge_management_and_ifrs_valuationsRange8.0.68.0.8
OR
oraclefinancial_services_hedge_management_and_ifrs_valuationsMatch8.1.0
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.0.6
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.0.7
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.1.0
OR
oraclefinancial_services_liquidity_risk_managementMatch8.0.6
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.0.7
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.0.8
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.1.0
OR
oraclefinancial_services_loan_loss_forecasting_and_provisioningRange8.0.68.0.8
OR
oraclefinancial_services_loan_loss_forecasting_and_provisioningMatch8.1.0
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.6
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.8
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.6
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.7
OR
oraclefinancial_services_profitability_managementMatch8.0.6
OR
oraclefinancial_services_profitability_managementMatch8.0.7
OR
oraclefinancial_services_profitability_managementMatch8.1.0
OR
oraclefinancial_services_regulatory_reporting_for_european_banking_authorityRange8.0.68.1.0
OR
oraclefinancial_services_regulatory_reporting_for_us_federal_reserveRange8.0.68.0.9
OR
oraclehealthcare_foundationMatch7.1.1
OR
oraclehealthcare_foundationMatch7.2.0
OR
oraclehealthcare_foundationMatch7.2.1
OR
oraclehealthcare_foundationMatch7.3.0
OR
oraclehospitality_materials_controlMatch18.1
OR
oraclehospitality_simphonyRange19.1.019.1.2
OR
oraclehospitality_simphonyMatch18.1
OR
oraclehospitality_simphonyMatch18.2
OR
oracleinsurance_accounting_analyzerMatch8.0.9
OR
oracleinsurance_allocation_manager_for_enterprise_profitabilityMatch8.0.8
OR
oracleinsurance_allocation_manager_for_enterprise_profitabilityMatch8.1.0
OR
oracleinsurance_data_foundationRange8.0.68.1.0
OR
oracleinsurance_insbridge_rating_and_underwritingRange5.0.0.05.6.0.0
OR
oracleinsurance_insbridge_rating_and_underwritingMatch5.6.1.0
OR
oraclejdeveloperMatch11.1.1.9.0
OR
oraclejdeveloperMatch12.2.1.3.0
OR
oraclejdeveloperMatch12.2.1.4.0
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.56
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.57
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.58
OR
oraclepolicy_automationRange12.2.012.2.20
OR
oraclepolicy_automation_connector_for_siebelMatch10.4.6
OR
oraclepolicy_automation_for_mobile_devicesRange12.2.012.2.20
OR
oracleretail_back_officeMatch14.0
OR
oracleretail_back_officeMatch14.1
OR
oracleretail_customer_management_and_segmentation_foundationMatch19.0
OR
oracleretail_returns_managementMatch14.0
OR
oracleretail_returns_managementMatch14.1
OR
oraclesiebel_ui_frameworkMatch20.8
OR
oraclestoragetek_acslsMatch8.5.1
OR
oracleweblogic_serverMatch10.3.6.0.0
OR
oracleweblogic_serverMatch12.1.3.0.0
OR
oracleweblogic_serverMatch12.2.1.3.0
OR
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0
Node
netappmax_dataMatch-
OR
netapponcommand_insightMatch-
OR
netapponcommand_system_managerRange3.03.1.3
OR
netappsnap_creator_frameworkMatch-
OR
netappsnapcenterMatch-
Node
netapph300s_firmwareMatch-
AND
netapph300sMatch-
Node
netapph500s_firmwareMatch-
AND
netapph500sMatch-
Node
netapph700s_firmwareMatch-
AND
netapph700sMatch-
Node
netapph300e_firmwareMatch-
AND
netapph300eMatch-
Node
netapph500e_firmwareMatch-
AND
netapph500eMatch-
Node
netapph700e_firmwareMatch-
AND
netapph700eMatch-
Node
netapph410s_firmwareMatch-
AND
netapph410sMatch-
Node
netapph410c_firmwareMatch-
AND
netapph410cMatch-
Node
opensuseleapMatch15.1
OR
opensuseleapMatch15.2
Node
tenablelog_correlation_engineRange<6.0.9
Node
oracleagile_product_supplier_collaboration_for_processMatch6.2.0.0
OR
oraclebanking_digital_experienceRange18.120.1
OR
oraclecommunications_application_session_controllerMatch3.8m0
OR
oraclecommunications_billing_and_revenue_managementMatch7.5.0.23.0
OR
oraclecommunications_billing_and_revenue_managementMatch12.0.0.3.0
OR
oraclecommunications_diameter_signaling_router_idih\Range8.0.08.2.2
OR
oraclecommunications_webrtc_session_controllerMatch7.2
OR
oracleenterprise_manager_ops_centerMatch12.4.0.0
OR
oracleenterprise_session_border_controllerMatch8.4
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.68.1.0
OR
oraclefinancial_services_analytical_applications_reconciliation_frameworkRange8.0.68.0.8
OR
oraclefinancial_services_analytical_applications_reconciliation_frameworkMatch8.1.0
OR
oraclefinancial_services_asset_liability_managementMatch8.0.6
OR
oraclefinancial_services_asset_liability_managementMatch8.0.7
OR
oraclefinancial_services_asset_liability_managementMatch8.1.0
OR
oraclefinancial_services_balance_sheet_planningMatch8.0.8
OR
oraclefinancial_services_basel_regulatory_capital_basicRange8.0.68.0.8
OR
oraclefinancial_services_basel_regulatory_capital_basicMatch8.1.0
OR
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approachRange8.0.68.0.8
OR
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approachMatch8.1.0
OR
oraclefinancial_services_data_foundationRange8.0.68.1.0
OR
oraclefinancial_services_data_governance_for_us_regulatory_reportingRange8.0.68.0.9
OR
oraclefinancial_services_data_integration_hubMatch8.0.6
OR
oraclefinancial_services_data_integration_hubMatch8.0.7
OR
oraclefinancial_services_data_integration_hubMatch8.1.0
OR
oraclefinancial_services_funds_transfer_pricingMatch8.0.6
OR
oraclefinancial_services_funds_transfer_pricingMatch8.0.7
OR
oraclefinancial_services_funds_transfer_pricingMatch8.1.0
OR
oraclefinancial_services_hedge_management_and_ifrs_valuationsRange8.0.68.0.8
OR
oraclefinancial_services_hedge_management_and_ifrs_valuationsMatch8.1.0
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.0.6
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.0.7
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.1.0
OR
oraclefinancial_services_liquidity_risk_managementMatch8.0.6
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.0.7
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.0.8
OR
oraclefinancial_services_liquidity_risk_measurement_and_managementMatch8.1.0
OR
oraclefinancial_services_loan_loss_forecasting_and_provisioningRange8.0.68.0.8
OR
oraclefinancial_services_loan_loss_forecasting_and_provisioningMatch8.1.0
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.6
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.8
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.6
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.7
OR
oraclefinancial_services_profitability_managementMatch8.0.6
OR
oraclefinancial_services_profitability_managementMatch8.0.7
OR
oraclefinancial_services_profitability_managementMatch8.1.0
OR
oraclefinancial_services_regulatory_reporting_for_european_banking_authorityRange8.0.68.1.0
OR
oraclefinancial_services_regulatory_reporting_for_us_federal_reserveRange8.0.68.0.9
OR
oraclehealthcare_foundationMatch7.1.1
OR
oraclehealthcare_foundationMatch7.2.0
OR
oraclehealthcare_foundationMatch7.2.1
OR
oraclehealthcare_foundationMatch7.3.0
OR
oraclehospitality_materials_controlMatch18.1
OR
oraclehospitality_simphonyMatch18.1
OR
oraclehospitality_simphonyMatch18.2
OR
oraclehospitality_simphonyMatch19.1.0-19.1.2
OR
oracleinsurance_accounting_analyzerMatch8.0.9
OR
oracleinsurance_allocation_manager_for_enterprise_profitabilityMatch8.0.8
OR
oracleinsurance_allocation_manager_for_enterprise_profitabilityMatch8.1.0
OR
oracleinsurance_data_foundationMatch8.0.6-8.1.0
OR
oracleinsurance_insbridge_rating_and_underwritingRange5.0.0.05.6.0.0
OR
oracleinsurance_insbridge_rating_and_underwritingMatch5.6.1.0
OR
oraclejdeveloperMatch11.1.1.9.0
OR
oraclejdeveloperMatch12.2.1.3.0
OR
oraclejdeveloperMatch12.2.1.4.0
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.56
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.57
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.58
OR
oraclepolicy_automationRange12.2.012.2.20
OR
oraclepolicy_automation_connector_for_siebelMatch10.4.6
OR
oraclepolicy_automation_for_mobile_devicesRange12.2.012.2.20
OR
oracleretail_back_officeMatch14.0
OR
oracleretail_back_officeMatch14.1
OR
oracleretail_customer_management_and_segmentation_foundationMatch19.0
OR
oracleretail_returns_managementMatch14.0
OR
oracleretail_returns_managementMatch14.1
OR
oraclesiebel_ui_frameworkMatch20.8
OR
oracleweblogic_serverMatch10.3.6.0.0
OR
oracleweblogic_serverMatch12.1.3.0.0
OR
oracleweblogic_serverMatch12.2.1.3.0
OR
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

High

0.061 Low

EPSS

Percentile

93.6%