Medium severity6.1NVD Advisory· Published Jan 18, 2018· Updated Jun 17, 2026
CVE-2015-9251
CVE-2015-9251
Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jquerynpm | < 1.12.2 | 1.12.2 |
jQueryNuGet | < 1.12.2 | 1.12.2 |
jQueryNuGet | >= 1.12.3, < 3.0.0 | 3.0.0 |
jquerynpm | >= 1.12.3, < 3.0.0 | 3.0.0 |
jquery-railsRubyGems | < 4.2.0 | 4.2.0 |
org.webjars.npm:jqueryMaven | < 1.12.2 | 1.12.2 |
org.webjars.npm:jqueryMaven | >= 1.12.3, < 3.0.0 | 3.0.0 |
Affected products
98cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_process_management_suite:11.1.1.9.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:business_process_management_suite:11.1.1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:business_process_management_suite:12.1.3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_converged_application_server:*:*:*:*:*:*:*:*Range: <7.0.0.1
cpe:2.3:a:oracle:communications_interactive_session_recorder:6.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_interactive_session_recorder:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_interactive_session_recorder:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_interactive_session_recorder:6.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_services_gatekeeper:*:*:*:*:*:*:*:*Range: <6.1.0.4.0
- cpe:2.3:a:oracle:communications_webrtc_session_controller:*:*:*:*:*:*:*:*Range: <7.2
cpe:2.3:a:oracle:endeca_information_discovery_studio:3.1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:endeca_information_discovery_studio:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_operations_monitor:3.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:enterprise_operations_monitor:3.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_operations_monitor:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*Range: >=7.3.3,<=7.3.5
- cpe:2.3:a:oracle:financial_services_asset_liability_management:*:*:*:*:*:*:*:*Range: >=8.0.4,<=8.0.7
- cpe:2.3:a:oracle:financial_services_data_integration_hub:*:*:*:*:*:*:*:*Range: >=8.0.5,<=8.0.7
- cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:*Range: >=8.0.4,<=8.0.7
- cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:*Range: >=8.0.4,<=8.0.7
- cpe:2.3:a:oracle:financial_services_liquidity_risk_management:*:*:*:*:*:*:*:*Range: >=8.0.2,<=8.0.6
- cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:*Range: >=8.0.2,<=8.0.7
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_profitability_management:*:*:*:*:*:*:*:*Range: >=8.0.4,<=8.0.6
cpe:2.3:a:oracle:financial_services_reconciliation_framework:8.0.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:financial_services_reconciliation_framework:8.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_reconciliation_framework:8.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:healthcare_foundation:7.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:healthcare_foundation:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:healthcare_foundation:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:healthcare_translational_research:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_cruise_fleet_management:9.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_reporting_and_analytics:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oss_support_tools:19.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_gateway:15.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:primavera_gateway:15.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_gateway:16.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_gateway:17.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.1,<=17.12
- cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:real-time_scheduler:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_allocation:15.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_customer_insights:16.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_invoice_matching:15.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_sales_audit:15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_workforce_management_software:1.60.9:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:retail_workforce_management_software:1.60.9:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_workforce_management_software:1.64.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_bus:12.1.3.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:service_bus:12.1.3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:service_bus:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:siebel_ui_framework:18.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:siebel_ui_framework:18.10:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:siebel_ui_framework:18.11:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:*Range: >=4.3.0.1,<=4.3.0.4
- cpe:2.3:a:oracle:utilities_mobile_workforce_management:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:webcenter_sites:11.1.1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:12.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:weblogic_server:12.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:weblogic_server:12.2.1.3:*:*:*:*:*:*:*
- ghsa-coords18 versionspkg:gem/jquery-railspkg:maven/org.webjars.npm/jquerypkg:npm/jquerypkg:nuget/jquerypkg:rpm/almalinux/custodiapkg:rpm/almalinux/python3-custodiapkg:rpm/almalinux/python3-jwcryptopkg:rpm/almalinux/python3-kdcproxypkg:rpm/almalinux/python3-pyusbpkg:rpm/almalinux/python3-qrcodepkg:rpm/almalinux/python3-qrcode-corepkg:rpm/almalinux/python3-yubicopkg:rpm/opensuse/ruby2.5&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015
< 4.2.0+ 17 more
- (no CPE)range: < 4.2.0
- (no CPE)range: < 1.12.2
- (no CPE)range: < 1.12.2
- (no CPE)range: < 1.12.2
- (no CPE)range: < 0.6.0-3.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 0.6.0-3.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 0.5.0-1.module_el8.5.0+2641+983b221b
- (no CPE)range: < 0.4-5.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 1.0.0-9.module_el8.5.0+2641+983b221b
- (no CPE)range: < 5.1-12.module_el8.6.0+2881+2f24dc92
- (no CPE)range: < 5.1-12.module_el8.6.0+2737+7e73ea90
- (no CPE)range: < 1.3.2-9.module_el8.5.0+2641+983b221b
- (no CPE)range: < 2.5.7-lp151.4.6.1
- (no CPE)range: < 2.5.7-4.8.1
- (no CPE)range: < 2.5.7-4.8.1
- (no CPE)range: < 2.5.7-4.8.1
- (no CPE)range: < 2.5.7-4.8.1
- (no CPE)range: < 2.5.7-4.8.1
Patches
Vulnerability mechanics
References
57- www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlnvdPatchWEB
- github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0ccnvdPatchThird Party AdvisoryWEB
- github.com/jquery/jquery/issues/2432nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/jquery/jquery/pull/2588nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/npm:jquery:20150627nvdPatchThird Party AdvisoryWEB
- www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlnvdPatchWEB
- www.securityfocus.com/bid/105658nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-rmxg-73gg-4p98ghsaADVISORY
- ics-cert.us-cert.gov/advisories/ICSA-18-212-04nvdThird Party AdvisoryUS Government ResourceWEB
- nvd.nist.gov/vuln/detail/CVE-2015-9251ghsaADVISORY
- sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdfnvdThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.htmlnvdWEB
- packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.htmlnvdWEB
- packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.htmlnvdWEB
- packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htmlnvdWEB
- seclists.org/fulldisclosure/2019/May/10nvdWEB
- seclists.org/fulldisclosure/2019/May/11nvdWEB
- seclists.org/fulldisclosure/2019/May/13nvdWEB
- access.redhat.com/errata/RHSA-2020:0481nvdWEB
- access.redhat.com/errata/RHSA-2020:0729nvdWEB
- github.com/jquery/jquery/commit/b078a62013782c7424a4a61a240c23c4c0b42614ghsaWEB
- github.com/jquery/jquery/issues/2432ghsaWEB
- github.com/rails/jquery-rails/blob/master/CHANGELOG.mdghsaWEB
- github.com/rails/jquery-rails/blob/v4.2.0/vendor/assets/javascripts/jquery3.jsghsaWEB
- github.com/rails/jquery-rails/releases/tag/v4.2.0ghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2015-9251.ymlghsaWEB
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601nvdWEB
- lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731@%3Cdev.flink.apache.org%3EghsaWEB
- lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49@%3Cuser.flink.apache.org%3EghsaWEB
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2@%3Cuser.flink.apache.org%3EghsaWEB
- lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854@%3Cuser.flink.apache.org%3EghsaWEB
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6@%3Ccommits.roller.apache.org%3EghsaWEB
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3EghsaWEB
- seclists.org/bugtraq/2019/May/18nvdWEB
- security.netapp.com/advisory/ntap-20210108-0004ghsaWEB
- security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450227ghsaWEB
- web.archive.org/web/20200227030101/http://www.securityfocus.com/bid/105658ghsaWEB
- www.oracle.com/security-alerts/cpuapr2020.htmlnvdWEB
- www.oracle.com/security-alerts/cpujan2020.htmlnvdWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdWEB
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdWEB
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlnvdWEB
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvdWEB
- www.tenable.com/security/tns-2019-08nvdWEB
- lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3Envd
- lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3Envd
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Envd
- lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3Envd
- lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3Envd
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Envd
- lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3Envd
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Envd
- security.netapp.com/advisory/ntap-20210108-0004/nvd
News mentions
0No linked articles in our index yet.