In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| oracle | healthcare_translational_research | - | - |
| oracle | healthcare_translational_research | - | - |
| oracle | healthcare_translational_research |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
81
Affected Products
132
References
oracle / healthcare_translational_research
| - |
| - |
| oracle | healthcare_translational_research | - | - |
| oracle | hyperion_financial_reporting | - | - |
| oracle | jd_edwards_enterpriseone_orchestrator | 9.2.5.0 | - |
| jquery | jquery | 1.0.3 - 3.5.0 | - |
| debian | debian_linux | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| drupal | drupal | 7.0 - 7.70 | - |
| drupal | drupal | 8.7.0 - 8.7.14 | - |
| drupal | drupal | 8.8.0 - 8.8.6 | - |
| oracle | application_express | 20.2 | - |
| oracle | application_testing_suite | - | - |
| oracle | banking_enterprise_collections | 2.7.0 - 2.8.0 | - |
| oracle | banking_platform | 2.4.0 - 2.10.0 | - |
| oracle | blockchain_platform | 21.1.2 | - |
| oracle | blockchain_platform | - | - |
| oracle | business_intelligence | - | - |
| oracle | communications_analytics | - | - |
| oracle | communications_eagle_application_processor | 16.1.0 - 16.4.0 | - |
| oracle | communications_element_manager | - | - |
| oracle | communications_element_manager | - | - |
| oracle | communications_element_manager | - | - |
| oracle | communications_interactive_session_recorder | 6.1 - 6.4 | - |
| oracle | communications_operations_monitor | 4.1 - 4.3 | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_services_gatekeeper | - | - |
| oracle | communications_session_report_manager | - | - |
| oracle | communications_session_report_manager | - | - |
| oracle | communications_session_report_manager | - | - |
| oracle | communications_session_route_manager | - | - |
| oracle | communications_session_route_manager | - | - |
| oracle | communications_session_route_manager | - | - |
| oracle | financial_services_regulatory_reporting_for_de_nederlandsche_bank | - | - |
| oracle | financial_services_revenue_management_and_billing_analytics | - | - |
| oracle | financial_services_revenue_management_and_billing_analytics | - | - |
| oracle | health_sciences_inform | - | - |
| oracle | jd_edwards_enterpriseone_tools | 9.2.5.0 | - |
| oracle | oss_support_tools | 2.12.41 | - |
| oracle | peoplesoft_enterprise_human_capital_management_resources | - | - |
| oracle | primavera_gateway | 16.2 - 16.2.11 | - |
| oracle | primavera_gateway | 17.12.0 - 17.12.7 | - |
| oracle | primavera_gateway | 18.8.0 - 18.8.9 | - |
| oracle | primavera_gateway | 19.12.0 - 19.12.4 | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | rest_data_services | - | - |
| oracle | siebel_mobile | 20.12 | - |
| oracle | storagetek_acsls | - | - |
| oracle | storagetek_tape_analytics_sw_tool | - | - |
| oracle | webcenter_sites | - | - |
| oracle | webcenter_sites | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| netapp | h300s_firmware | - | - |
| netapp | h500s_firmware | - | - |
| netapp | h700s_firmware | - | - |
| netapp | h300e_firmware | - | - |
| netapp | h500e_firmware | - | - |
| netapp | h700e_firmware | - | - |
| netapp | h410s_firmware | - | - |
| netapp | h410c_firmware | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | cloud_backup | - | - |
| netapp | cloud_insights_storage_workload_security_agent | - | - |
| netapp | hci_baseboard_management_controller | - | - |
| netapp | max_data | - | - |
| netapp | oncommand_insight | - | - |
| netapp | oncommand_system_manager | 3.0 - 3.1.3 | - |
| netapp | snap_creator_framework | - | - |
| netapp | snapcenter_server | - | - |
| tenable | log_correlation_engine | 6.0.9 | - |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Exploitability
Impact