CVE-2020-11022
published 2020-04-29CVE-2020-11022: In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods…
PriorityP184medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
99.02%
99.9th percentile
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| athlon1600 | youtube-downloader | 0 – 4.0.0 | — |
| components | jquery | >= 1.12.0 < 3.5.0 | 3.5.0 |
| components | jquery | >= 1.2.0 < 3.5.0 | 3.5.0 |
| debian | debian_linux | — | — |
| debian | node-jquery | < node-jquery 3.5.0+dfsg-2 (bookworm) | node-jquery 3.5.0+dfsg-2 (bookworm) |
| debian | otrs2 | < node-jquery 3.5.0+dfsg-2 (bookworm) | node-jquery 3.5.0+dfsg-2 (bookworm) |
| drupal | core | >= 8.0.0 < 8.7.14 | 8.7.14 |
| drupal | core | >= 8.8.0 < 8.8.6 | 8.8.6 |
| drupal | drupal | >= 7.0 < 7.70 | 7.70 |
| drupal | drupal | >= 8.7.0 < 8.7.14 | 8.7.14 |
| drupal | drupal | >= 8.8.0 < 8.8.6 | 8.8.6 |
| drupal | drupal_core | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jquery | jquery | — | — |
| jquery | jquery | >= 0 < 1.7.2+dfsg-2ubuntu1+esm1 | 1.7.2+dfsg-2ubuntu1+esm1 |
| jquery | jquery | >= 0 < 1.11.3+dfsg-4ubuntu0.1~esm1 | 1.11.3+dfsg-4ubuntu0.1~esm1 |
| jquery | jquery | >= 0 < 3.2.1-1ubuntu0.1~esm1 | 3.2.1-1ubuntu0.1~esm1 |
| jquery | jquery | >= 1.12.0 < 3.5.0 | 3.5.0 |
| jquery | jquery | >= 1.12.0 < 3.5.0 | 3.5.0 |
| jquery | jquery | >= 1.2 < 3.5.0 | 3.5.0 |
| jquery | jquery | >= 1.2.0 < 3.5.0 | 3.5.0 |
| jquery | jquery | >= 1.2.0 < 3.5.0 | 3.5.0 |
| maximebf | debugbar | >= 0 < 1.19.0 | 1.19.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor application URL query strings and web form inputs for injected JavaScript payloads targeting applications running jQuery <= 3.5.0 ↗
- →Use static code analysis / dependency scanning to identify jQuery versions >= 1.2 and < 3.5.0 in web application dependencies as a detection/inventory signal ↗
- →In SIEM, create queries to flag suspicious reflected XSS activity (anomalous JavaScript execution) originating from untrusted domains against endpoints running vulnerable jQuery versions ↗
- ·CVE-2020-11022 affects jQuery versions >= 1.2 and < 3.5.0; the NVD entry scopes the vulnerable range as 'starting with 1.12.0 and before 3.5.0' while other sources (exploit-db, CISA advisories) cite >= 1.2 — verify the exact lower bound against your deployed version ↗
- ·The Huntress source incorrectly states the fixed version is jQuery 3.5.1; the official patch is jQuery 3.5.0 per NVD. Ensure remediation targets >= 3.5.0. ↗
- ·No known public exploitation specifically targeting this vulnerability has been reported to CISA as of the Hitachi Energy advisory (July 2025); risk context should be weighed accordingly for ICS/OT environments ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vulncheck6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Commerce Merchandising 11.3.0/11.3.1/11.3.2 Business Control Center cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Commerce Merchandising 11.3.0/11.3.1/11.3.2 Business Control Center cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle Commerce Merchandising 11.3.0/11.3.1/11.3.2. Affected is an unknown function of the component Business Control Center. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Agile Product Lifecycle Management for Process 6.2.0.0 Supplier Portal cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Agile Product Lifecycle Management for Process 6.2.0.0 Supplier Portal cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle Agile Product Lifecycle Management for Process 6.2.0.0. Affected is an unknown function of the component Supplier Portal. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
VulDB
Oracle Siebel UI Framework 20.8 UIF Open UI cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Siebel UI Framework 20.8 UIF Open UI cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Siebel UI Framework 20.8 and classified as critical. The affected element is an unknown function of the component UIF Open UI. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2020-11022. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle WebCenter Sites 12.2.1.3.0/12.2.1.4.0. This affects an unknown part of the component WebCenter Sites. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.
VulDB
Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x Web Runtime cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x Web Runtime cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x. Affected by this vulnerability is an unknown functionality of the component Web Runtime. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Fusion Middleware MapViewer 12.2.1.4.0 Install cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Fusion Middleware MapViewer 12.2.1.4.0 Install cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Fusion Middleware MapViewer 12.2.1.4.0. It has been rated as critical. This impacts an unknown function of the component Install. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2020-11022. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Policy Automation for Mobile Devices up to 12.2.20 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Policy Automation for Mobile Devices up to 12.2.20 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability described as critical has been identified in Oracle Policy Automation for Mobile Devices up to 12.2.20. Impacted is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
VulDB
Oracle Retail Back Office 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Retail Back Office 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle Retail Back Office 14.0/14.1. Affected by this issue is some unknown functionality of the component Security. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
VulDB
Oracle Retail Returns Management 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Retail Returns Management 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Retail Returns Management 14.0/14.1. It has been declared as critical. Impacted is an unknown function of the component Security. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Policy Automation up to 12.2.20 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Policy Automation up to 12.2.20 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Policy Automation up to 12.2.20. This vulnerability affects unknown code. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
VulDB
Oracle PeopleSoft Enterprise PT PeopleTools 8.56/8.57/8.58 Weblogic cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise PT PeopleTools 8.56/8.57/8.58 Weblogic cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle PeopleSoft Enterprise PT PeopleTools 8.56/8.57/8.58. This impacts an unknown function of the component Weblogic. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise SCM eProcurement 9.2 Manage Requisition Status cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise SCM eProcurement 9.2 Manage Requisition Status cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability identified as critical has been detected in Oracle PeopleSoft Enterprise SCM eProcurement 9.2. Affected is an unknown function of the component Manage Requisition Status. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2020-11022. The attack may be initiated remotely. In addition, an exploit is available.
You should upgrade the affected component.
VulDB
Oracle StorageTek Tape Analytics SW Tool 2.3.1 jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle StorageTek Tape Analytics SW Tool 2.3.1 jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle StorageTek Tape Analytics SW Tool 2.3.1 and classified as critical. This impacts an unknown function of the component jQuery. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise FIN Expenses 9.2 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise FIN Expenses 9.2 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle PeopleSoft Enterprise FIN Expenses 9.2. It has been classified as critical. The affected element is an unknown function of the component Expenses. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Primavera Unifier up to 20.12 Core UI cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Primavera Unifier up to 20.12 Core UI cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability marked as critical has been reported in Oracle Primavera Unifier up to 20.12. Impacted is an unknown function of the component Core UI. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
VulDB
Oracle Hyperion Financial Reporting 11.1.2.4 Installation cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Hyperion Financial Reporting 11.1.2.4 Installation cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Hyperion Financial Reporting 11.1.2.4. It has been declared as critical. This impacts an unknown function of the component Installation. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
VulDB
Oracle Policy Automation Connector for Siebel 10.4.6 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Policy Automation Connector for Siebel 10.4.6 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability marked as critical has been reported in Oracle Policy Automation Connector for Siebel 10.4.6. This issue affects some unknown processing. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise HCM Human Resources 9.2 Company Dir/Org Chart Viewer/Employee Snapshot cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise HCM Human Resources 9.2 Company Dir/Org Chart Viewer/Employee Snapshot cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle PeopleSoft Enterprise HCM Human Resources 9.2. Affected by this issue is some unknown functionality of the component Company Dir/Org Chart Viewer/Employee Snapshot. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
VulDB
Oracle Application Testing Suite 13.3.0.1 Load Testing for Web Apps cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Application Testing Suite 13.3.0.1 Load Testing for Web Apps cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability marked as critical has been reported in Oracle Application Testing Suite 13.3.0.1. This impacts an unknown function of the component Load Testing for Web Apps. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise SCM Purchasing 9.2 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise SCM Purchasing 9.2 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle PeopleSoft Enterprise SCM Purchasing 9.2. Affected by this vulnerability is an unknown functionality of the component Purchasing. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
The affected component should be upgraded.
VulDB
Oracle WebLogic Server jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle WebLogic Server jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. It has been rated as critical. Impacted is an unknown function of the component jQuery. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
VulDB
Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x E1 Dev Platform Tech - Cloud cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x E1 Dev Platform Tech - Cloud cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x. The affected element is an unknown function of the component E1 Dev Platform Tech - Cloud. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Siebel Mobile App up to 20.12 Open UI cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Siebel Mobile App up to 20.12 Open UI cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Siebel Mobile App up to 20.12 and classified as critical. The affected element is an unknown function of the component Open UI. The manipulation results in cross site scripting.
This vulnerability was named CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 Portal/Charting cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 Portal/Charting cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 and classified as critical. This affects an unknown function of the component Portal/Charting. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Retail Customer Management and Segmentation Foundation Segments cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Retail Customer Management and Segmentation Foundation Segments cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Retail Customer Management and Segmentation Foundation 19 and classified as critical. This vulnerability affects unknown code of the component Segments. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
VulDB
Oracle Retail Central Office 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Retail Central Office 14.0/14.1 Security cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability has been found in Oracle Retail Central Office 14.0/14.1 and classified as critical. This affects an unknown part of the component Security. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
The affected component should be upgraded.
VulDB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 BI Platform Security cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Business Intelligence Enterprise Edition 5.5.0.0.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 BI Platform Security cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Business Intelligence Enterprise Edition 5.5.0.0.0/11.1.1.9.0/12.2.1.3.0/12.2.1.4.0. It has been declared as critical. This affects an unknown function of the component BI Platform Security. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
VulDB
Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x Web Runtime cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x Web Runtime cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, has been found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.4.x. The impacted element is an unknown function of the component Web Runtime. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle WebLogic Server 12.1.3.0.0/12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Sample apps cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle WebLogic Server 12.1.3.0.0/12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Sample apps cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability has been found in Oracle WebLogic Server 12.1.3.0.0/12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 and classified as critical. This vulnerability affects unknown code of the component Sample apps. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2020-11022. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The affected component should be upgraded.
VulDB
Oracle Commerce Guided Search 11.3.0/11.3.1/11.3.2 Workbench/Experience Manager cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Commerce Guided Search 11.3.0/11.3.1/11.3.2 Workbench/Experience Manager cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical has been found in Oracle Commerce Guided Search 11.3.0/11.3.1/11.3.2. This impacts an unknown function of the component Workbench/Experience Manager. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
VulDB
Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.4.x E1 IOT Orchestrator Security cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.4.x E1 IOT Orchestrator Security cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical has been found in Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.4.x. Impacted is an unknown function of the component E1 IOT Orchestrator Security. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise FIN Common Application Objects Common Objects cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise FIN Common Application Objects Common Objects cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle PeopleSoft Enterprise FIN Common Application Objects 9.2 and classified as critical. Impacted is an unknown function of the component Common Objects. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle Financial Services Revenue Management and Billing Analytics jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-14·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Revenue Management and Billing Analytics jQuery cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Financial Services Revenue Management and Billing Analytics 2.7.0/2.8.0. Affected by this issue is some unknown functionality of the component jQuery. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
VulDB
Oracle Communications Diameter Signaling Router up to 8.2.2 IDIH cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Communications Diameter Signaling Router up to 8.2.2 IDIH cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Communications Diameter Signaling Router up to 8.2.2. Affected by this issue is some unknown functionality of the component IDIH. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
The affected component should be upgraded.
VulDB
Oracle WebLogic Server Console cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle WebLogic Server Console cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle WebLogic Server 10.3.6.0.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. The impacted element is an unknown function of the component Console. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.
VulDB
Oracle Financial Services Liquidity Risk Measurement and Management User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Liquidity Risk Measurement and Management User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Financial Services Liquidity Risk Measurement and Management 8.0.7/8.0.8/8.1.0. It has been declared as critical. The impacted element is an unknown function of the component User Interface. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
It is recommended to upgrade the affected component.
VulDB
Oracle Financial Services Institutional Performance Analytics User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Institutional Performance Analytics User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Financial Services Institutional Performance Analytics 8.0.6/8.0.7/8.1.0 and classified as critical. Impacted is an unknown function of the component User Interface. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2020-11022. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
VulDB
Oracle Healthcare Foundation 7.1.1/7.2.0/7.2.1/7.3.0 Admin Console cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Healthcare Foundation 7.1.1/7.2.0/7.2.1/7.3.0 Admin Console cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Healthcare Foundation 7.1.1/7.2.0/7.2.1/7.3.0. This issue affects some unknown processing of the component Admin Console. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
The affected component should be upgraded.
VulDB
Oracle Financial Services Analytical Applications Reconciliation Framework User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Analytical Applications Reconciliation Framework User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle Financial Services Analytical Applications Reconciliation Framework 8.0.6/8.0.7/8.0.8/8.1.0. The affected element is an unknown function of the component User Interface. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-11022. The attack can be executed remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle Financial Services Loan Loss Forecasting and Provisioning User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Loan Loss Forecasting and Provisioning User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Financial Services Loan Loss Forecasting and Provisioning 8.0.6/8.0.7/8.0.8/8.1.0. It has been rated as critical. This affects an unknown function of the component User Interface. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
VulDB
Oracle Banking Digital Experience up to 20.1 Framework cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Banking Digital Experience up to 20.1 Framework cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Banking Digital Experience up to 20.1. It has been declared as critical. This issue affects some unknown processing of the component Framework. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Financial Services Basel Regulatory Capital Basic 8.0.6/8.0.7/8.0.8/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Basel Regulatory Capital Basic 8.0.6/8.0.7/8.0.8/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability marked as critical has been reported in Oracle Financial Services Basel Regulatory Capital Basic 8.0.6/8.0.7/8.0.8/8.1.0. This impacts an unknown function of the component User Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle JDeveloper 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 ADF Faces cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle JDeveloper 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 ADF Faces cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle JDeveloper 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0. Impacted is an unknown function of the component ADF Faces. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
VulDB
Oracle Communications Billing and Revenue Management 7.5.0.23.0/12.0.0.3.0 Billing Operation Center cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Communications Billing and Revenue Management 7.5.0.23.0/12.0.0.3.0 Billing Operation Center cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability identified as critical has been detected in Oracle Communications Billing and Revenue Management 7.5.0.23.0/12.0.0.3.0. This affects an unknown part of the component Billing Operation Center/Oracle Communication Billing Care. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.
VulDB
Oracle Communications WebRTC Session Controller 7.2 ME cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Communications WebRTC Session Controller 7.2 ME cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical has been found in Oracle Communications WebRTC Session Controller 7.2. This issue affects some unknown processing of the component ME. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
VulDB
Oracle Enterprise Session Border Controller 8.4 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Enterprise Session Border Controller 8.4 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle Enterprise Session Border Controller 8.4. Impacted is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Insurance Data Foundation up to 8.1.0 Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Insurance Data Foundation up to 8.1.0 Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle Insurance Data Foundation up to 8.1.0. The affected element is an unknown function of the component Infrastructure. The manipulation results in cross site scripting.
This vulnerability was named CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
You should upgrade the affected component.
VulDB
Oracle Insurance Allocation Manager for Enterprise Profitability User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Insurance Allocation Manager for Enterprise Profitability User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, has been found in Oracle Insurance Allocation Manager for Enterprise Profitability 8.0.8/8.1.0. Impacted is an unknown function of the component User Interface. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
VulDB
Oracle Insurance Insbridge Rating and Underwriting up to 5.6.0.0/5.6.1.0 Framework Administrator IBFA cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Insurance Insbridge Rating and Underwriting up to 5.6.0.0/5.6.1.0 Framework Administrator IBFA cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle Insurance Insbridge Rating and Underwriting up to 5.6.0.0/5.6.1.0. Affected by this vulnerability is an unknown functionality of the component Framework Administrator IBFA. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Financial Services Balance Sheet Planning 8.0.8 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Balance Sheet Planning 8.0.8 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Financial Services Balance Sheet Planning 8.0.8. This affects an unknown function of the component User Interface. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
The affected component should be upgraded.
VulDB
Oracle Enterprise Manager Ops Center 12.4.0.0 Reports in Ops Center cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Enterprise Manager Ops Center 12.4.0.0 Reports in Ops Center cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability described as critical has been identified in Oracle Enterprise Manager Ops Center 12.4.0.0. This issue affects some unknown processing of the component Reports in Ops Center. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 PIA Core Technology cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58 PIA Core Technology cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle PeopleSoft Enterprise PeopleTools 8.56/8.57/8.58. The affected element is an unknown function of the component PIA Core Technology. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
You should upgrade the affected component.
VulDB
Oracle Hospitality Simphony up to 18.1/18.2/19.1.2 Simphony Apps cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Hospitality Simphony up to 18.1/18.2/19.1.2 Simphony Apps cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical has been found in Oracle Hospitality Simphony up to 18.1/18.2/19.1.2. The affected element is an unknown function of the component Simphony Apps. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability described as critical has been identified in Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach 8.0.6/8.0.7/8.0.8/8.1.0. Affected is an unknown function of the component User Interface. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle Communications Application Session Controller 3.8m0 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Communications Application Session Controller 3.8m0 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle Communications Application Session Controller 3.8m0. Affected is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
VulDB
Oracle Insurance Accounting Analyzer 8.0.9 IFRS17 cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Insurance Accounting Analyzer 8.0.9 IFRS17 cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle Insurance Accounting Analyzer 8.0.9. This issue affects some unknown processing of the component IFRS17. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2020-11022. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.
VulDB
Oracle Healthcare Translational Research 3.2.1/3.3.1/3.3.2/3.4.0 Cohort Explorer cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Healthcare Translational Research 3.2.1/3.3.1/3.3.2/3.4.0 Cohort Explorer cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle Healthcare Translational Research 3.2.1/3.3.1/3.3.2/3.4.0. Impacted is an unknown function of the component Cohort Explorer. The manipulation results in cross site scripting.
This vulnerability was named CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
You should upgrade the affected component.
VulDB
Oracle Financial Services Regulatory Reporting for European Banking Authority User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Regulatory Reporting for European Banking Authority User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability marked as critical has been reported in Oracle Financial Services Regulatory Reporting for European Banking Authority up to 8.1.0. Affected by this issue is some unknown functionality of the component User Interface. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2020-11022. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle Financial Services Hedge Management and IFRS Valuations User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Hedge Management and IFRS Valuations User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability has been found in Oracle Financial Services Hedge Management and IFRS Valuations 8.0.6/8.0.7/8.0.8/8.1.0 and classified as critical. This issue affects some unknown processing of the component User Interface. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2020-11022. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The affected component should be upgraded.
VulDB
Oracle Financial Services Regulatory Reporting for US Federal Reserve User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Regulatory Reporting for US Federal Reserve User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability described as critical has been identified in Oracle Financial Services Regulatory Reporting for US Federal Reserve 8.0.6/8.0.7/8.0.8/8.0.9. This affects an unknown part of the component User Interface. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Financial Services Analytical Applications Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Analytical Applications Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Financial Services Analytical Applications Infrastructure up to 8.1.0. It has been rated as critical. Impacted is an unknown function of the component Infrastructure. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2020-11022. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is advised.
VulDB
Oracle Financial Services Funds Transfer Pricing 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Funds Transfer Pricing 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, was found in Oracle Financial Services Funds Transfer Pricing 8.0.6/8.0.7/8.1.0. This vulnerability affects unknown code of the component User Interface. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2020-11022. The attack may be launched remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.
VulDB
Oracle Financial Services Price Creation and Discovery 8.0.6/8.0.7 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Price Creation and Discovery 8.0.6/8.0.7 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability identified as critical has been detected in Oracle Financial Services Price Creation and Discovery 8.0.6/8.0.7. Affected is an unknown function of the component User Interface. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.
VulDB
Oracle Financial Services Data Integration Hub 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Data Integration Hub 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability, which was classified as critical, has been found in Oracle Financial Services Data Integration Hub 8.0.6/8.0.7/8.1.0. This affects an unknown part of the component User Interface. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2020-11022. The attack may be initiated remotely. In addition, an exploit is available.
It is advisable to upgrade the affected component.
VulDB
Oracle Financial Services Data Foundation up to 8.1.0 Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Data Foundation up to 8.1.0 Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical has been found in Oracle Financial Services Data Foundation up to 8.1.0. Affected by this vulnerability is an unknown functionality of the component Infrastructure. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
VulDB
Oracle Financial Services Data Governance for US Regulatory Reporting User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Data Governance for US Regulatory Reporting User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability classified as critical was found in Oracle Financial Services Data Governance for US Regulatory Reporting 8.0.6/8.0.7/8.0.8/8.0.9. Affected by this issue is some unknown functionality of the component User Interface. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
VulDB
Oracle Financial Services Profitability Management 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Profitability Management 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability labeled as critical has been found in Oracle Financial Services Profitability Management 8.0.6/8.0.7/8.1.0. Affected by this vulnerability is an unknown functionality of the component User Interface. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-11022. The attack can be launched remotely. Moreover, an exploit is present.
The affected component should be upgraded.
VulDB
Oracle Hospitality Materials Control 18.1 Mobile Authorization cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Hospitality Materials Control 18.1 Mobile Authorization cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability described as critical has been identified in Oracle Hospitality Materials Control 18.1. Impacted is an unknown function of the component Mobile Authorization. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2020-11022. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle Financial Services Asset Liability Management 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Asset Liability Management 8.0.6/8.0.7/8.1.0 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability identified as critical has been detected in Oracle Financial Services Asset Liability Management 8.0.6/8.0.7/8.1.0. The impacted element is an unknown function of the component User Interface. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
You should upgrade the affected component.
VulDB
Oracle Financial Services Market Risk Measurement and Management Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Market Risk Measurement and Management Infrastructure cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability categorized as critical has been discovered in Oracle Financial Services Market Risk Measurement and Management 8.0.6/8.0.8. This impacts an unknown function of the component Infrastructure. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
VulDB
Oracle Financial Services Liquidity Risk Management 8.0.6 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
vuldb·2026-04-13·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Financial Services Liquidity Risk Management 8.0.6 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
A vulnerability was found in Oracle Financial Services Liquidity Risk Management 8.0.6. It has been classified as critical. The affected element is an unknown function of the component User Interface. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2020-11022. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
OSV
jquery vulnerabilities
osv·2025-07-08·CVSS 6.1
CVE-2012-6708 [MEDIUM] jquery vulnerabilities
jquery vulnerabilities
It was discovered that jQuery did not correctly handle HTML tags. An
attacker could possibly use this issue to execute a cross-site scripting
(XSS) attack. This issue only affected Ubuntu 14.04 LTS. (CVE-2012-6708)
It was discovered that jQuery did not correctly handle unsanitized source
objects due to prototype pollution. An attacker could possibly use this
issue to execute a cross-site scripting (XSS) attack. (CVE-2019-11358)
Masato Kinugawa discovered that jQuery did not correctly sanitize certain
HTML elements. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-11022)
Masato Kinugawa discovered that jQuery did not correctly sanitize certain
HTML el
GHSA
Persistent Cross-site Scripting vulnerability in PrivateBin
ghsa·2022-04-12
CVE-2022-24833 [HIGH] CWE-79 Persistent Cross-site Scripting vulnerability in PrivateBin
Persistent Cross-site Scripting vulnerability in PrivateBin
In PrivateBin
alert(document.domain);
```
2. Upload it as an attachment to a PrivateBin instance that has attachments enabled and hasn't set the recommended content security policy (in particular, one that has either no content security policy set or that allows `*` or `blob:` as a `script-src`).
3. Open the paste. (In a real attack scenario this would be done by the victim.)
4. The SVG is rendered safely as a preview, and script isn't yet executed.
5. Now (depending on your device) right-click or long tap on the image and open it in a new tab.
6. Now a `blob:` URI opens in a new tab with the image and the modal is shown, therefore the script got executed.
## Impact
We tried to reproduce the vulnerability and in our asses
OSV
Persistent Cross-site Scripting vulnerability in PrivateBin
osv·2022-04-12
CVE-2022-24833 [HIGH] Persistent Cross-site Scripting vulnerability in PrivateBin
Persistent Cross-site Scripting vulnerability in PrivateBin
In PrivateBin
alert(document.domain);
```
2. Upload it as an attachment to a PrivateBin instance that has attachments enabled and hasn't set the recommended content security policy (in particular, one that has either no content security policy set or that allows `*` or `blob:` as a `script-src`).
3. Open the paste. (In a real attack scenario this would be done by the victim.)
4. The SVG is rendered safely as a preview, and script isn't yet executed.
5. Now (depending on your device) right-click or long tap on the image and open it in a new tab.
6. Now a `blob:` URI opens in a new tab with the image and the modal is shown, therefore the script got executed.
## Impact
We tried to reproduce the vulnerability and in our asses
OSV
Use of insecure jQuery version in OctoberCMS
osv·2020-06-05·CVSS 6.1
[MEDIUM] Use of insecure jQuery version in OctoberCMS
Use of insecure jQuery version in OctoberCMS
### Impact
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.
### Patches
Issue has been patched in Build 466 (v1.0.466) by applying the recommended patch from @jquery.
### Workarounds
Apply https://github.com/octobercms/october/commit/5c7ba9fbe9f2b596b2f0e3436ee06b91b97e5892 to your installation manually if unable to upgrade to Build 466.
### References
- https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022
- https://jquery.com/upgrade-guide/3.5/
### For more information
If you have any questions or comments about this advisory:
* Emai
GHSA
Use of insecure jQuery version in OctoberCMS
ghsa·2020-06-05·CVSS 6.1
[MEDIUM] Use of insecure jQuery version in OctoberCMS
Use of insecure jQuery version in OctoberCMS
### Impact
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.
### Patches
Issue has been patched in Build 466 (v1.0.466) by applying the recommended patch from @jquery.
### Workarounds
Apply https://github.com/octobercms/october/commit/5c7ba9fbe9f2b596b2f0e3436ee06b91b97e5892 to your installation manually if unable to upgrade to Build 466.
### References
- https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022
- https://jquery.com/upgrade-guide/3.5/
### For more information
If you have any questions or comments about this advisory:
* Emai
OSV
CVE-2020-11022: The jQuery project released version 3
osv·2020-05-20·CVSS 6.1
CVE-2020-11022 [MEDIUM] CVE-2020-11022: The jQuery project released version 3
The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the [jQuery blog](https://blog.jquery.com/2020/05/04/jquery-3-5-1-released-fixing-a-regression/), both are
> [...] security issues in jQuery’s DOM manipulation methods, as in `.html()`, `.append()`, and the others. Security advisories for both of these issues have been published on GitHub.
Those advisories are:
* [CVE-2020-11022](https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2)
* [CVE-2020-11023](https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6)
These vulnerabilities may be exploitable on some Drupal sites. This Drupal security release backports the fixes to the relevant jQuery functions,
OSV
Potential XSS vulnerability in jQuery
osv·2020-04-29
CVE-2020-11022 [MEDIUM] Potential XSS vulnerability in jQuery
Potential XSS vulnerability in jQuery
### Impact
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.
### Patches
This problem is patched in jQuery 3.5.0.
### Workarounds
To workaround the issue without upgrading, adding the following to your code:
```js
jQuery.htmlPrefilter = function( html ) {
return html;
};
```
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround.
### References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://jquery.com/upgrade-guide/3.5/
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/
GHSA
Potential XSS vulnerability in jQuery
ghsa·2020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 Potential XSS vulnerability in jQuery
Potential XSS vulnerability in jQuery
### Impact
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.
### Patches
This problem is patched in jQuery 3.5.0.
### Workarounds
To workaround the issue without upgrading, adding the following to your code:
```js
jQuery.htmlPrefilter = function( html ) {
return html;
};
```
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround.
### References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://jquery.com/upgrade-guide/3.5/
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/
OSV
CVE-2020-11022: In jQuery versions greater than or equal to 1
osv·2020-04-29·CVSS 6.1
CVE-2020-11022 [MEDIUM] CVE-2020-11022: In jQuery versions greater than or equal to 1
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
VulnCheck
JQuery JQuery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
vulncheck·2020·CVSS 6.9
CVE-2020-11022 [MEDIUM] JQuery JQuery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
JQuery JQuery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Affected: JQuery JQuery
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.tenable.com/blog/daisy-chaining-how-vulnerabilities-can-be-greater-than-the-sum-of-their-parts; https://www.securin.io/wp-content/uploads/2023/08/2023-State-of-Cybersecurity-for-Medical-Devices-and-
Ubuntu
Drupal vulnerabilities
vendor_ubuntu·2025-07-21
CVE-2020-11022 Drupal vulnerabilities
Title: Drupal vulnerabilities
Summary: Several security issues were fixed in Drupal.
It was discovered that Drupal incorrectly parsed untrusted HTML. A
remote attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
jQuery vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 6.1
CVE-2012-6708 [MEDIUM] jQuery vulnerabilities
Title: jQuery vulnerabilities
Summary: Several security issues were fixed in jQuery.
It was discovered that jQuery did not correctly handle HTML tags. An
attacker could possibly use this issue to execute a cross-site scripting
(XSS) attack. This issue only affected Ubuntu 14.04 LTS. (CVE-2012-6708)
It was discovered that jQuery did not correctly handle unsanitized source
objects due to prototype pollution. An attacker could possibly use this
issue to execute a cross-site scripting (XSS) attack. (CVE-2019-11358)
Masato Kinugawa discovered that jQuery did not correctly sanitize certain
HTML elements. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-11022)
Masato Kinugawa di
CISA ICS
Hitachi Energy MSM
cisa_ics·2025-07-01·CVSS 6.9
[MEDIUM] Hitachi Energy MSM
ICS Advisory
##
Hitachi Energy MSM
Release DateJuly 01, 2025
Alert CodeICSA-25-182-07
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Modular Switchgear Monitoring (MSM)
- Vulnerability: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow attackers to execute untrusted code, potentially leading to unauthorized actions or system compromise.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports the following products are affected:
- Hitachi Energ
Ubuntu
jQuery vulnerabilities
vendor_ubuntu·2025-01-30
CVE-2020-11022 jQuery vulnerabilities
Title: jQuery vulnerabilities
Summary: Several security issues were fixed in jquery.
It was discovered that jQuery incorrectly handled parsing untrusted HTML. A
remote attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (jQuery) — CVE-2020-11022
vendor_oracle·2024-10-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Utilities Applications Risk Matrix: General (jQuery) — CVE-2020-11022
Oracle Oracle Utilities Applications Risk Matrix: General (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
CISA ICS
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere (Update A)
cisa_ics·2022-12-08·CVSS 7.5
[HIGH] AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere (Update A)
ICS Advisory
##
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere (Update A)
Last RevisedMarch 16, 2023
Alert CodeICSA-22-342-02
## 1. EXECUTIVE SUMMARY
--------- Begin Update A Part 1 of 6 ---------
- CVSS v3 9.8
--------- End Update A Part 1 of 6 ---------
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: AVEVA
--------- Begin Update A Part 2 of 6 ---------
- Equipment: InTouch Access Anywhere, Plant SCADA Access Anywhere
- Vulnerability: Relative Path Traversal, Classic Buffer Overflow, Cross-site Scripting
--------- End Update A Part 2 of 6 ---------
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-22-342-02 AVEVA InTouch Access Anywhere, publ
Oracle
Oracle Oracle Communications Risk Matrix: Platform (HTTP) — CVE-2020-11022
vendor_oracle·2022-10-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (HTTP) — CVE-2020-11022
Oracle Oracle Communications Risk Matrix: Platform (HTTP) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Security (jQuery) — CVE-2020-11022
vendor_oracle·2022-07-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Security (jQuery) — CVE-2020-11022
Oracle Oracle Supply Chain Risk Matrix: Security (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: Backend (jQuery) — CVE-2020-11022
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Blockchain Platform Risk Matrix: Backend (jQuery) — CVE-2020-11022
Oracle Oracle Blockchain Platform Risk Matrix: Backend (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA ICS
Pepperl+Fuchs WirelessHART-Gateway
cisa_ics·2022-04-07·CVSS 7.5
[HIGH] Pepperl+Fuchs WirelessHART-Gateway
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Pepperl+Fuchs WirelessHART-Gateway
Last RevisedApril 07, 2022
Alert CodeICSA-22-097-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Pepperl+Fuchs
- Equipment: WirelessHART-Gateway
- Vulnerabilities: Use of Hard-coded Credentials, Uncontrolled Resource Consumption, Reliance on Reverse DNS Resolution for a Security-critical Action, Path Traversal, Cross-site Scripting, Exposure of Sensitive Information to an Unauthorized Actor, Cleartext Storage of Sensitive Information in a Cookie, HTTP Request Smuggling, Sensitive Co
CISA ICS
Mitsubishi Electric EcoWebServerIII
cisa_ics·2022-02-24·CVSS 6.1
[MEDIUM] Mitsubishi Electric EcoWebServerIII
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric EcoWebServerIII
Last RevisedFebruary 24, 2022
Alert CodeICSA-22-055-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric Corporation
- Equipment: Energy Saving Data Collecting Server (EcoWebServerIII)
- Vulnerabilities: Improper Neutralization of Input During Web Page Generation, Uncontrolled Resource Consumption, Improperly Controlled Modification of Dynamically-Determined Object Attributes
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow informa
Oracle
Oracle Oracle Communications Risk Matrix: Platform (jQuery) — CVE-2020-11022
vendor_oracle·2022-01-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (jQuery) — CVE-2020-11022
Oracle Oracle Communications Risk Matrix: Platform (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (jQuery) — CVE-2020-11022
vendor_oracle·2021-10-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Web Services (jQuery) — CVE-2020-11022
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Dashboards (jQuery) — CVE-2020-11022
vendor_oracle·2021-07-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Dashboards (jQuery) — CVE-2020-11022
Oracle Oracle Financial Services Applications Risk Matrix: Dashboards (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench, Experience Manager (jQuery) — CVE-2020-11022
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Workbench, Experience Manager (jQuery) — CVE-2020-11022
Oracle Oracle Commerce Risk Matrix: Workbench, Experience Manager (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (jQuery) — CVE-2020-11022
vendor_oracle·2021-01-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (jQuery) — CVE-2020-11022
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Billing Operation Center and Oracle Communication Billing Care (jQuery) — CVE-2020-11022
vendor_oracle·2020-10-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Billing Operation Center and Oracle Communication Billing Care (jQuery) — CVE-2020-11022
Oracle Oracle Communications Applications Risk Matrix: Billing Operation Center and Oracle Communication Billing Care (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Platform (jQuery) — CVE-2020-11022
vendor_oracle·2020-07-15·CVSS 6.1
CVE-2020-11022 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Platform (jQuery) — CVE-2020-11022
Oracle Oracle Communications Applications Risk Matrix: Platform (jQuery) vulnerability
CVE: CVE-2020-11022
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Palo Alto
PAN
vendor_paloalto·2020-07-08·CVSS 9.8
CVE-2013-7459 [CRITICAL] PAN
PAN
The Palo Alto Networks Product Security Assurance team has evaluated and determined that these third-party or open source vulnerabilities do not have any security impact on PAN-OS or that the scenarios required for successful
CVEs: CVE-2013-7459, CVE-2018-1120, CVE-2018-1121, CVE-2018-1122, CVE-2018-1123, CVE-2018-1124, CVE-2018-16402, CVE-2020-11022, CVE-2020-11023, CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11899, CVE-2020-11900, CVE-2020-11901, CVE-2020-11902, CVE-2020-11903, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
Affected products: PAN-OS
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
vendor_drupal·2020-05-20·CVSS 6.9
CVE-2020-11022 [MEDIUM] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
Title: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
Vulnerability Type: Cross Site Scripting
Description: The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the jQuery blog , both are [...] security issues in jQuery’s DOM manipulation methods, as in .html() , .append() , and the others. Security advisories for both of these issues have been published on GitHub. Those advisories are: CVE-2020-11022 CVE-2020-11023 These vulnerabilities may be exploitable on some Drupal sites. This Drupal security release backports the fixes to the relevant jQuery functions, without making any other changes to the jQuery version that is included in Drupal core or running on the
Red Hat
jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
vendor_redhat·2020-04-23·CVSS 6.9
CVE-2020-11022 [MEDIUM] CWE-79 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
A Cross-site scripting (XSS) vulnerability exists in JQuery. This flaw allows an attacker with the ability to supply input to the ‘HTML’ function to inject Javascript into the page where that input is rendered, and have it delivered by the browser.
Statement: No supported release of Red Hat OpenStack Platform is affected by this vulnerability as no shipped packages contain the vulnerable code.
Package: cfme-gemset (CloudForms Managemen
Debian
CVE-2020-11022: node-jquery - In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML f...
vendor_debian·2020·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022: node-jquery - In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML f...
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Scope: local
bookworm: resolved (fixed in 3.5.0+dfsg-2)
bullseye: resolved (fixed in 3.5.0+dfsg-2)
forky: resolved (fixed in 3.5.0+dfsg-2)
sid: resolved (fixed in 3.5.0+dfsg-2)
trixie: resolved (fixed in 3.5.0+dfsg-2)
No detection rules found.
HackerOne
CVE-2020-11022: CVE-2020-11022
## Summary:
CVE-2020-11022 at " https://app
hackerone·2023-05-18·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022: CVE-2020-11022
## Summary:
CVE-2020-11022 at " https://app
CVE-2020-11022
## Summary:
CVE-2020-11022 at " https://app.spiketrap.io/users/sign_in "
## Steps To Reproduce:
Cross-Site Scripting (XSS)
# Proof of Concept 1:
## Supporting Material/References:
https://security.snyk.io/vuln/SNYK-JS-JQUERY-567880
https://github.com/TIBCOSoftware/Augmented-Reality/issues/65
https://www.exploit-db.com/exploits/49766
https://www.cybersecurity-help.cz/vdb/SB2020042126
* [attachment / reference]
## Impact
Cross site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user’s machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.
Bugzilla
CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
A cross-site scripting (XSS) vulnerability in the htmlPrefilter method of jQuery before 3.5.0.
References:
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://github.com/jquery/jquery/pull/4642
https://github.com/jquery/jquery/pull/4647
https://seclists.org/fulldisclosure/2020/Apr/46
Upstream fix:
https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77
Discussion:
Created drupal7 tracking bugs for this issue:
Affects: epel-all [bug 1828417]
Affects: fedora-all [bug 1828416]
Created js-jquery tracking bugs for this issue:
Affects: epel-7 [bug 1828410]
Affects: fedora-all [bug 1828419]
Created js-jquery1 tracking bugs for this issue:
Affects: epel-7 [
Bugzilla
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2020-11022 rubygem-jquery-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 rubygem-jquery-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 rubygem-jquery-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussi
Bugzilla
CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the fol
Bugzilla
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
CVE-2020-11022 python-XStatic-jquery-ui: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all]
CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
CVE-2020-11022 python-tw2-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 js-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
CVE-2020-11022 js-jquery1: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the fo
Bugzilla
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 python-XStatic-jQuery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-11022 js-jquery2: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 js-jquery2: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 js-jquery2: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2020-11022 python-tw-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 python-tw-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
CVE-2020-11022 python-tw-jquery: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2020-11022 rubygem-jquery-ui-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
bugzilla·2020-04-27·CVSS 6.9
CVE-2020-11022 [MEDIUM] CVE-2020-11022 rubygem-jquery-ui-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
CVE-2020-11022 rubygem-jquery-ui-rails: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
blogs_tenable·2021-01-21
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
CVE-2020-11022 Vulnerability | Huntress
blogs_huntress·CVSS 6.1
CVE-2020-11022 [MEDIUM] CVE-2020-11022 Vulnerability | Huntress
## CVE-2020-11022 Vulnerability
Published: 12/16/25
Written by: Lizzie Danielson
## What is CVE-2020-11022 vulnerability?
CVE-2020-11022 is a reflected cross-site scripting (XSS) vulnerability affecting the jQuery JavaScript library versions 3.5.0 and earlier. This vulnerability arises when unsanitized user input is dynamically injected into a webpage, allowing attackers to execute arbitrary scripts in the context of a victim's browser. Successful exploitation can result in data exfiltration, session hijacking, or redirection to malicious domains.
## When was it discovered?
CVE-2020-11022 was disclosed on May 4, 2020, by the jQuery team during their routine review of security in the framework. This discovery followed a coordinated vulnerability disclosure process and was shared publi
http://security.netapp.com/advisory/ntap-20200511-0006https://blog.jquery.com/2020/04/10/jquery-3-5-0-releasedhttps://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77https://github.com/jquery/jquery/releases/tag/3.5.0https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2https://github.com/maximebf/php-debugbar/commit/847216e60544258c881f2733d699bbcfeefac0fchttps://github.com/maximebf/php-debugbar/issues/447https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-11022.ymlhttps://jquery.com/upgrade-guide/3.5https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133@%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBYhttps://lists.fedoraproject.org/archives/list/[email protected]/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7Khttps://lists.fedoraproject.org/archives/list/[email protected]/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4https://lists.fedoraproject.org/archives/list/[email protected]/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6Bhttps://lists.fedoraproject.org/archives/list/[email protected]/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3Whttps://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlhttps://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlhttps://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.htmlhttps://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.htmlhttps://security.gentoo.org/glsa/202007-03https://www.debian.org/security/2020/dsa-4693https://www.drupal.org/sa-core-2020-002https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2020-10https://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-02https://www.tenable.com/security/tns-2021-10http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.htmlhttp://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.htmlhttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2https://jquery.com/upgrade-guide/3.5/https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W/https://security.gentoo.org/glsa/202007-03https://security.netapp.com/advisory/ntap-20200511-0006/https://www.debian.org/security/2020/dsa-4693https://www.drupal.org/sa-core-2020-002https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2020-10https://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-02https://www.tenable.com/security/tns-2021-10
2020-04-29
Published
Exploited in the wild