Cross-site scripting in jQuery - CVE-2020-11023
Published: May 5, 2020 / Updated: July 23, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when passing <option> elements to jQuery’s DOM manipulation methods. A remote attacker can execute arbitrary JavaScript code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
watsonx.data
Gentoo Linux
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
SUSE Linux
Opensuse
System Monitor application in Pro-face Industrial PC series
System Monitor application in Harmony Industrial PC series
IBM Cloud Pak for Watson AIOps
IBM Security Verify Information Queue
DataStax Hyper-Converged Database
IBM Watson Machine Learning Accelerator
Guardium Data Security Center (GDSC)
Tivoli Network Manager IP Edition
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Oracle BI Publisher
IBM Aspera Shares
Storage Copy Data Management
IBM Aspera Console
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Engineering Lifecycle Optimization - Publishing
MobileFirst Platform
OpenPages for IBM Cloud Pak for Data
Security Verify Privilege On-Premises
Robotic Process Automation for Cloud Pak
EcoWebServerIII MES3-255C-EN
EcoWebServerIII MES3-255C-DM-EN
EcoWebServerIII MES3-255C-CN
EcoWebServerIII MES3-255C-DM-CN
AMQ Interconnect
IBM Concert Software
IBM Observability with Instana
IBM Process Mining
IBM Cloud Transformation Advisor
VideoEdge
WebSphere eXtreme Scale
Tenable Nessus
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Submariner
Service Interconnect
Multicluster GlobalHub
Log Analysis
Netcool Operations Insight
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
Data Replication on Cloud Pak for Data
OpenShift Logging
IBM Sterling B2B Integrator
Engineering Workflow Management
IBM Maximo Asset Management
IBM Security Verify Governance - Containerized Identity Manager
IBM Security Verify Governance
Red Hat OpenStack
Red Hat build of Keycloak
PT-G503
Planning Analytics Local
QRadar Pulse App
Cacti
Moodle
Cloudera Data Platform Private Cloud Base for IBM
Red Hat OpenShift GitOps
qpid-dispatch (Red Hat package)
rhv-log-collector-analyzer (Red Hat package)
cacti (Alpine package)
ovirt-engine-ui-extensions (Red Hat package)
ovirt-engine-extension-aaa-ldap (Red Hat package)
vdsm-jsonrpc-java (Red Hat package)
ovirt-web-ui (Red Hat package)
ovirt-log-collector (Red Hat package)
ovirt-engine (Red Hat package)
ovirt-engine-dwh (Red Hat package)
otrs (Alpine package)
drupal7 (Alpine package)
drupal7 (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
eap7-jboss-jsp (Red Hat package)
eap7-jboss-jsf (Red Hat package)
pcs-snmp
pcs
pcs (Red Hat package)
eap7-javaee-security-soteria (Red Hat package)
eap7-jettison (Red Hat package)
eap7-ironjacamar (Red Hat package)
jquery (Ubuntu package)
doxygen (Red Hat package)
doxygen-latex
doxygen-doxywizard
doxygen
eap7-elytron-web (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
python-django20 (Red Hat package)
python-XStatic-jQuery224 (Red Hat package)
eap7-undertow (Red Hat package)
eap7-apache-sshd (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-annotations (Red Hat package)
libjs-jquery (Ubuntu package)
eap7-hal-console (Red Hat package)
eap7-jboss-ejb-client (Red Hat package)
ipa (Red Hat package)
gcc (Red Hat package)
libstdc++
libstdc++-docs
libstdc++-devel
gcc-go
libtsan
libstdc++-static
libgnat
gcc-gnat
gcc-gfortran
gcc-c++
gcc
cpp
gcc-objc++
gcc-objc
gcc-plugin-devel
libasan
libasan-static
libatomic
libatomic-static
libgcc
libgfortran
libgfortran-static
libquadmath-static
libgnat-devel
libgnat-static
libgo
libgo-devel
libgo-static
libgomp
libitm
libitm-devel
libitm-static
libmudflap
libmudflap-devel
libmudflap-static
libobjc
libquadmath
libquadmath-devel
libtsan-static
eap7-jboss-remoting (Red Hat package)
eap7-hibernate-search (Red Hat package)
unboundid-ldapsdk (Red Hat package)
eap7-woodstox-core (Red Hat package)
eap7-wildfly (Red Hat package)
drupal7 (Ubuntu package)
drupal7
libgomp-offload-nvptx
gcc-offload-nvptx
libubsan
liblsan
gcc-gdb-plugin
drupal8
pki-core (Red Hat package)
gcc-toolset-13-gcc (Red Hat package)
gcc-toolset-13-libquadmath-devel
gcc-toolset-13-libgccjit-devel
gcc-toolset-13-offload-nvptx
libtsan2
libhwasan
libasan8
gcc-toolset-13-libubsan-devel
gcc-toolset-13-libtsan-devel
gcc-toolset-13-libstdc++-docs
gcc-toolset-13-libstdc++-devel
gcc-toolset-13-liblsan-devel
gcc-toolset-13-libitm-devel
gcc-toolset-13-libhwasan-devel
gcc-toolset-13-libgccjit
gcc-toolset-13-libatomic-devel
gcc-toolset-13-libasan-devel
gcc-toolset-13-gcc-plugin-devel
gcc-toolset-13-gcc-plugin-annobin
gcc-toolset-13-gcc
gcc-toolset-13-gcc-c++
gcc-toolset-13-gcc-gfortran
gcc-toolset-14-gcc (Red Hat package)
rh-sso7-keycloak (Red Hat package)
tbb (Red Hat package)
tbb-doc
python3-tbb
tbb
tbb-devel
Backdrop CMS
Joomla!
Drupal
Red Hat Virtualization Manager
Nessus Network Monitor
OSS Support Tools
IBM Tivoli Network Manager (ITNM)
Red Hat OpenShift Container Platform
IBM Qradar SIEM
Zoho ManageEngine OpManager
IBM Cognos Command Center
IBM Cognos Controller
JBoss Enterprise Application Platform
Oracle WebLogic Server
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Oracle Database Server
IBM InfoSphere Information Server
Oracle REST Data Services
IBM CICS TX Advanced
IBM CICS TX Standard
SUSE Package Hub for SUSE Linux Enterprise
Oracle WebCenter Portal
Oracle Application Express
IBM Cloud Pak System
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
IBM Storage Scale System
Red Hat Ceph Storage
Dell Storage Manager
How to mitigate CVE-2020-11023
EcoWebServerIII MES3-255C-EN - update to 3.3.1
EcoWebServerIII MES3-255C-DM-EN - update to 3.3.1
EcoWebServerIII MES3-255C-CN - update to 3.3.1
PT-G503 - update to 5.3
EcoWebServerIII MES3-255C-DM-CN - update to 3.3.1
QRadar Pulse App - update to 2.2.9
AMQ Interconnect - update to 1.9.0
IBM Concert Software - update to 1.1.0
qpid-dispatch (Red Hat package) - addressed in versions 1.13.0-3.el6_10, 1.13.0-3.el7, 1.13.0-3.el8
IBM Security Verify Information Queue - update to 10.0.0
rhv-log-collector-analyzer (Red Hat package) - update to 1.0.15-1.el8ev
IBM Observability with Instana - update to 1.0.297
Cacti - update to 1.2.13
DataStax Hyper-Converged Database - update to 1.2.5
ovirt-engine-ui-extensions (Red Hat package) - update to 1.3.5-1.el8ev
ovirt-engine-extension-aaa-ldap (Red Hat package) - update to 1.4.6-1.el8ev
vdsm-jsonrpc-java (Red Hat package) - update to 1.7.2-1.el8ev
ovirt-web-ui (Red Hat package) - update to 1.9.1-1.el8ev
IBM Process Mining - update to 1.12.0.4
Backdrop CMS - addressed in versions 1.15.3, 1.16.1
IBM Cloud Transformation Advisor - update to 3.1.0
IBM Watson Machine Learning Accelerator - update to 2.6.0
Joomla! - update to 3.9.19
Moodle - addressed in versions 3.5.17, 3.8.8, 3.9.5, 3.10.2
Guardium Data Security Center (GDSC) - update to 3.8.1
Tivoli Network Manager IP Edition - update to 4.2.0.20
ovirt-log-collector (Red Hat package) - update to 4.4.7-2.el8ev
ovirt-engine (Red Hat package) - update to 4.5.2.4-0.1.el8ev
ovirt-engine-dwh (Red Hat package) - update to 4.5.4-1.el8ev
Nessus Network Monitor - update to 5.13.0
otrs (Alpine package) - update to 6.0.33-r0
VideoEdge - update to 5.7.1
Drupal - addressed in versions 7.70, 8.7.14, 8.8.6
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 9, 7.4.3 Fix Pack 1
JBoss Enterprise Application Platform - update to 7.4.9
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP9 IF02, 7.5.0 UP11 IF03
Red Hat Single Sign-On - update to 7.6.2
drupal7 (Alpine package) - update to 7.70-r0
drupal7 (Debian package) - update to 7.52-2+deb9u10
IBM Business Automation Manager Open Editions - update to 8.0.7
WebSphere eXtreme Scale - update to 8.6.1.5 PH53340
Tenable Nessus - update to 10.5.0
Oracle REST Data Services - update to 20.2.1
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.3, 11.7.1.3 Service pack 4
Zoho ManageEngine OpManager - update to 12.5 125212
Oracle Application Express - update to 20.2
Autodesk Infraworks - addressed in versions 2019.3 Hotfix 5, 2020.2 Hotfix 4, 2021.2 Hotfix 4, 2022.0 Hotfix 3, 2022.1 Hotfix 2
eap7-jboss-jsp (Red Hat package) - addressed in versions api_2.3_spec-2.0.0-3.Final_redhat_00001.1.el7eap, api_2.3_spec-2.0.0-3.Final_redhat_00001.1.el8eap, api_2.3_spec-2.0.0-3.Final_redhat_00001.1.el9eap
eap7-jboss-jsf (Red Hat package) - addressed in versions api_2.3_spec-3.0.0-6.SP07_redhat_00001.1.el7eap, api_2.3_spec-3.0.0-6.SP07_redhat_00001.1.el8eap, api_2.3_spec-3.0.0-6.SP07_redhat_00001.1.el9eap
pcs-snmp - update to 0.9.169-3
pcs - update to 0.9.169-3
pcs (Red Hat package) - update to 0.10.10-4.el8
Submariner - addressed in versions 0.17.6, 0.18.5
Service Interconnect - addressed in versions 1, 1.4
eap7-javaee-security-soteria (Red Hat package) - addressed in versions 1.0.1-3.redhat_00003.1.el7eap, 1.0.1-3.redhat_00003.1.el8eap, 1.0.1-3.redhat_00003.1.el9eap
Multicluster GlobalHub - addressed in versions 1.2.2, 1.3.3
Log Analysis - update to 1.3.8
eap7-jettison (Red Hat package) - addressed in versions 1.5.2-1.redhat_00002.1.el7eap, 1.5.2-1.redhat_00002.1.el8eap, 1.5.2-1.redhat_00002.1.el9eap
eap7-ironjacamar (Red Hat package) - addressed in versions 1.5.10-1.Final_redhat_00001.1.el7eap, 1.5.10-1.Final_redhat_00001.1.el8eap, 1.5.10-1.Final_redhat_00001.1.el9eap
Netcool Operations Insight - update to 1.6.8
jquery (Ubuntu package) - addressed in versions 1.7.2+dfsg-2ubuntu1+esm1, 1.11.3+dfsg-4ubuntu0.1~esm1, 3.2.1-1ubuntu0.1~esm1
doxygen (Red Hat package) - addressed in versions 1.8.5-3.el7_7.1, 1.8.5-4.el7_9.1, 1.8.14-13.el8_8, 1.8.14-13.el8_10, 1.9.1-12.el9_2, 1.9.1-12.el9_4, 1.9.1-12.el9_5
doxygen-latex - addressed in versions 1.8.5-4, 1.8.14-13
doxygen-doxywizard - addressed in versions 1.8.5-4, 1.8.14-13
doxygen - addressed in versions 1.8.5-4, 1.8.14-13
eap7-elytron-web (Red Hat package) - addressed in versions 1.9.3-1.Final_redhat_00001.1.el7eap, 1.9.3-1.Final_redhat_00001.1.el8eap, 1.9.3-1.Final_redhat_00001.1.el9eap
IBM Aspera Shares - update to 1.9.15
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-24.Final_redhat_00023.1.el7eap, 1.10.0-24.Final_redhat_00023.1.el8eap, 1.10.0-24.Final_redhat_00023.1.el9eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.16-1.Final_redhat_00001.1.el7eap, 1.15.16-1.Final_redhat_00001.1.el8eap, 1.15.16-1.Final_redhat_00001.1.el9eap
Red Hat OpenShift GitOps - update to 1.16.1
python-django20 (Red Hat package) - update to 2.0.13-19.el8ost
watsonx.data - update to 2.1
python-XStatic-jQuery224 (Red Hat package) - update to 2.2.4.1-3.el8ost
eap7-undertow (Red Hat package) - addressed in versions 2.2.22-1.SP3_redhat_00001.1.el7eap, 2.2.22-1.SP3_redhat_00001.1.el8eap, 2.2.22-1.SP3_redhat_00001.1.el9eap
Storage Copy Data Management - update to 2.2.26.0
IBM Cloud Pak System - update to 2.3.4.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.9, 2.6.7, 2.7.4
eap7-apache-sshd (Red Hat package) - addressed in versions 2.9.2-1.redhat_00001.1.el7eap, 2.9.2-1.redhat_00001.1.el8eap, 2.9.2-1.redhat_00001.1.el9eap
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.10.8, 2.11.7, 2.12.3
eap7-jackson-modules-java8 (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
eap7-jackson-modules-base (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
eap7-jackson-jaxrs-providers (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
eap7-jackson-databind (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
eap7-jackson-core (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
eap7-jackson-annotations (Red Hat package) - addressed in versions 2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap
OSS Support Tools - update to 2.12.41
libjs-jquery (Ubuntu package) - update to 3.3.1~dfsg-3ubuntu0.1
eap7-hal-console (Red Hat package) - addressed in versions 3.3.16-1.Final_redhat_00001.1.el7eap, 3.3.16-1.Final_redhat_00001.1.el8eap, 3.3.16-1.Final_redhat_00001.1.el9eap
IBM Aspera Console - update to 3.4.2
Red Hat OpenShift Dev Spaces - update to 3.19.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
eap7-jboss-ejb-client (Red Hat package) - addressed in versions 4.0.49-1.Final_redhat_00001.1.el7eap, 4.0.49-1.Final_redhat_00001.1.el8eap, 4.0.49-1.Final_redhat_00001.1.el9eap
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.5.7, 4.6.0, 4.6.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
ipa (Red Hat package) - addressed in versions 4.6.5-11.el7_7.5, 4.6.8-5.el7_9.4
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
gcc (Red Hat package) - addressed in versions 4.8.5-40.el7_7, 4.8.5-45.el7_9, 8.3.1-8.el8_2, 8.4.1-1.4.el8_4, 8.5.0-10.4.el8_6, 8.5.0-18.3.el8_8, 8.5.0-23.el8_10, 11.2.1-9.5.el9_0, 11.3.1-4.4.el9_2, 11.4.1-4.el9_4, 11.5.0-5.el9_5
libstdc++ - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libstdc++-docs - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libstdc++-devel - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
gcc-go - update to 4.8.5-45.0.1
libtsan - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libstdc++-static - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libgnat - update to 4.8.5-45.0.1
gcc-gnat - update to 4.8.5-45.0.1
gcc-gfortran - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
gcc-c++ - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
gcc - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
cpp - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
gcc-objc++ - update to 4.8.5-45.0.1
gcc-objc - update to 4.8.5-45.0.1
gcc-plugin-devel - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libasan - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libasan-static - update to 4.8.5-45.0.1
libatomic - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libatomic-static - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libgcc - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libgfortran - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libgfortran-static - update to 4.8.5-45.0.1
libquadmath-static - update to 4.8.5-45.0.1
libgnat-devel - update to 4.8.5-45.0.1
libgnat-static - update to 4.8.5-45.0.1
libgo - update to 4.8.5-45.0.1
libgo-devel - update to 4.8.5-45.0.1
libgo-static - update to 4.8.5-45.0.1
libgomp - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libitm - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libitm-devel - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libitm-static - update to 4.8.5-45.0.1
libmudflap - update to 4.8.5-45.0.1
libmudflap-devel - update to 4.8.5-45.0.1
libmudflap-static - update to 4.8.5-45.0.1
libobjc - update to 4.8.5-45.0.1
libquadmath - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libquadmath-devel - addressed in versions 4.8.5-45.0.1, 8.5.0-23.0.1
libtsan-static - update to 4.8.5-45.0.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.74, 4.14.48, 4.16.35, 4.16.44, 4.17.17, 4.18.6, 4.19.0
OpenShift Virtualization - addressed in versions 4.15.9, 4.16.7
IBM Decision Optimization for Cloud Pak for Data - update to 5.0
eap7-jboss-remoting (Red Hat package) - addressed in versions 5.0.27-1.Final_redhat_00001.1.el7eap, 5.0.27-1.Final_redhat_00001.1.el8eap, 5.0.27-1.Final_redhat_00001.1.el9eap
Data Replication on Cloud Pak for Data - update to 5.1.0
IBM Storage Scale System - addressed in versions 5.1.9.7, 5.2.2.0
OpenShift Logging - addressed in versions 5.8.18, 5.8.19, 5.8.20, 5.9.12, 5.9.14
eap7-hibernate-search (Red Hat package) - addressed in versions 5.10.13-3.Final_redhat_00001.1.el7eap, 5.10.13-3.Final_redhat_00001.1.el8eap, 5.10.13-3.Final_redhat_00001.1.el9eap
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
unboundid-ldapsdk (Red Hat package) - update to 6.0.4-1.el8ev
eap7-woodstox-core (Red Hat package) - addressed in versions 6.4.0-1.redhat_00001.1.el7eap, 6.4.0-1.redhat_00001.1.el8eap, 6.4.0-1.redhat_00001.1.el9eap
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.27, 7.0.3.2
eap7-wildfly (Red Hat package) - addressed in versions 7.4.9-4.GA_redhat_00003.1.el7eap, 7.4.9-4.GA_redhat_00003.1.el8eap, 7.4.9-4.GA_redhat_00003.1.el9eap
IBM Maximo Asset Management - update to 7.6.1.2.37
drupal7 (Ubuntu package) - addressed in versions 7.26-1ubuntu0.1+esm3, 7.44-1ubuntu1~16.04.0+esm3
drupal7 - addressed in versions 7.72-1.el6, 7.72-1.el7, 7.72-1.fc31, 7.72-1.fc32, 7.72-1.fc33
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202304111626
Red Hat Ceph Storage - update to 8.1
libgomp-offload-nvptx - update to 8.5.0-23.0.1
gcc-offload-nvptx - update to 8.5.0-23.0.1
libubsan - update to 8.5.0-23.0.1
liblsan - update to 8.5.0-23.0.1
gcc-gdb-plugin - update to 8.5.0-23.0.1
drupal8 - update to 8.9.0-1.fc32
OpenPages for IBM Cloud Pak for Data - update to 9.000.0
IBM Security Verify Governance - Containerized Identity Manager - update to 10.0.2
IBM Security Verify Governance - update to 10.0.2.0.1
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
pki-core (Red Hat package) - update to 10.5.16-8.el7_7
IBM CICS TX Advanced - update to 11.1.0.0 ifix29
IBM CICS TX Standard - update to 11.1.0.0 ifix30
Security Verify Privilege On-Premises - update to 11.5.0.2
gcc-toolset-13-gcc (Red Hat package) - addressed in versions 13.3.1-2.2.el8_10, 13.3.1-2.2.el9_4, 13.3.1-2.2.el9_5
gcc-toolset-13-libquadmath-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libgccjit-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-offload-nvptx - update to 13.3.1-2.2.0.1
libtsan2 - update to 13.3.1-2.2.0.1
libhwasan - update to 13.3.1-2.2.0.1
libasan8 - update to 13.3.1-2.2.0.1
gcc-toolset-13-libubsan-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libtsan-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libstdc++-docs - update to 13.3.1-2.2.0.1
gcc-toolset-13-libstdc++-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-liblsan-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libitm-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libhwasan-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libgccjit - update to 13.3.1-2.2.0.1
gcc-toolset-13-libatomic-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-libasan-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-gcc-plugin-devel - update to 13.3.1-2.2.0.1
gcc-toolset-13-gcc-plugin-annobin - update to 13.3.1-2.2.0.1
gcc-toolset-13-gcc - update to 13.3.1-2.2.0.1
gcc-toolset-13-gcc-c++ - update to 13.3.1-2.2.0.1
gcc-toolset-13-gcc-gfortran - update to 13.3.1-2.2.0.1
gcc-toolset-14-gcc (Red Hat package) - addressed in versions 14.2.1-1.3.el9_5, 14.2.1-7.1.el8_10
Red Hat OpenStack - update to 16.2
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.6-1.redhat_00001.1.el7sso, 18.0.6-1.redhat_00001.1.el8sso, 18.0.6-1.redhat_00001.1.el9sso
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
Red Hat build of Keycloak - update to 26.0.10
tbb (Red Hat package) - addressed in versions 2018.2-9.el8_2.1, 2018.2-10.el8_4.1, 2018.2-10.el8_6.1, 2018.2-10.el8_8.1, 2018.2-10.el8_10.1, 2020.3-8.el9_0.1, 2020.3-8.el9_2.1, 2020.3-8.el9_4.1, 2020.3-8.el9_5.1
tbb-doc - update to 2018.2-10
python3-tbb - update to 2018.2-10
tbb - update to 2018.2-10
tbb-devel - update to 2018.2-10
Dell Storage Manager - update to 2020 R1.21
Links to Public Exploits and PoC-codes
- Exploit #7684 - CVE-2020-11022-CVE-2020-11023 (Little thing put together quickly to demonstrate this CVE ) (April 24, 2022)
- Exploit #5391 - jQuery 1.0.3 - Cross-Site Scripting (XSS) (May 9, 2021)
- Exploit #2959 - snyk-js-jquery-565129 (patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428) (June 3, 2020)
External References
Related Security Bulletins
- Cross-site scripting in jQuery
- Drupal update for jQuery
- Backdrop update for jQuery
- Debian update for drupal7
- Joomla! update for jQuery
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Multiple vulnerabilities in Cacti
- Gentoo update for Cacti
- OpenSUSE Linux update for cacti, cacti-spine
- Cross-site scripting in drupal7 (Alpine package)
- Cross-site scripting in cacti (Alpine package)
- Zoho ManageEngine OpManager update for jQuery
- Multiple vulnerabilities in Red Hat AMQ Interconnect
- Multiple vulnerabilities in Oracle Application Express
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Oracle REST Data Services
- OpenSUSE Linux update for otrs
- Red Hat OpenStack update for python-XStatic-jQuery224
- Nessus Network Monitor update for jQuery
- Moodle update for jQuery
- Red Hat Enterprise Linux 7 update for ipa
- Cross-site scripting in otrs (Alpine package)
- Multiple vulnerabilities in Oracle Application Express
- Red Hat Enterprise Linux 8 update for the idm:DL1 and idm:client modules
- Cross-site scripting in OSS Support Tools
- Cross-site scripting in Sensormatic Electronics VideoEdge
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Mitsubishi Electric EcoWebServerIII
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Cross-site scripting in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Aspera Console and Aspera Shares
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Virtualization Manager
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM QRadar Pulse for QRadar SIEM
- Multiple vulnerabilities in IBM Tivoli Network Manager
- Cross-site scripting in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for pcs
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 7
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 8
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 9
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 for RHEL 9
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 for RHEL 8
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 for RHEL 7
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM WebSphere eXtreme Scale Liberty Deployment
- Multiple vulnerabilities in IBM MobileFirst Platform
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Oracle BI Publisher
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in Moxa PT-G503 Series
- Multiple vulnerabilities in IBM OpenPages for IBM Cloud Pak for Data
- Watson Machine Learning Accelerator on Cloud Pak for Data update for jQuery
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Operations Analytics
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Security Verify Privilege On-Premises
- Multiple vulnerabilities in IBM Engineering Lifecycle Optimization - Publishing (PUB)
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Cross-site scripting in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Security Verify Governance - Containerized Identity Manager
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Cross-site scripting in Oracle WebCenter Portal
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- Multiple vulnerabilities in IBM Storage Scale
- Ubuntu update for jquery
- Multiple vulnerabilities in IBM watsonx.data
- Cross-site scripting in Red Hat OpenStack 16.2 packages
- Red Hat Enterprise Linux 9 update for doxygen
- Red Hat Enterprise Linux 9 update for tbb
- Red Hat Enterprise Linux 9 update for tbb
- Red Hat Enterprise Linux 8 update for tbb
- Red Hat Enterprise Linux 9 update for tbb
- Red Hat Enterprise Linux 9 update for tbb
- Red Hat Enterprise Linux 8 update for tbb
- Red Hat Enterprise Linux 8 update for tbb
- Red Hat Enterprise Linux 8 update for tbb
- Red Hat Enterprise Linux 8 update for tbb
- Red Hat Enterprise Linux 8 update for doxygen
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for doxygen
- Red Hat Enterprise Linux 7 update for doxygen
- Red Hat Enterprise Linux 9 update for gcc-toolset-14-gcc
- Red Hat Enterprise Linux 9 update for gcc
- Red Hat Enterprise Linux 9 update for gcc
- Red Hat Enterprise Linux 9 update for gcc
- Red Hat Enterprise Linux 8 update for gcc-toolset-13-gcc
- Red Hat Enterprise Linux 8 update for gcc
- Red Hat Enterprise Linux 9 update for gcc-toolset-13-gcc
- Red Hat Enterprise Linux 8 update for gcc
- Red Hat Enterprise Linux 8 update for gcc
- Red Hat Enterprise Linux 8 update for doxygen
- Red Hat Enterprise Linux 9 update for doxygen
- Red Hat Enterprise Linux 8 update for gcc
- Red Hat Enterprise Linux 8 update for gcc
- Red Hat Enterprise Linux 9 update for doxygen
- Multiple vulnerabilities in IBM Data Replication on Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for gcc-toolset-14-gcc
- Red Hat Enterprise Linux 9 update for gcc-toolset-13-gcc
- Red Hat Enterprise Linux 9 update for gcc
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Red Hat Enterprise Linux 7 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 7 update for gcc
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for gcc
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat build of Keycloak 26.0
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.8
- Red Hat Enterprise Linux 7 update for pki-core
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in OpenShift Virtualization 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Anolis OS update for pcs
- Anolis OS update for tbb
- Anolis OS update for doxygen
- Anolis OS update for gcc-toolset-13-gcc
- Anolis OS update for gcc
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in OpenShift Logging 5.8
- Anolis OS update for gcc
- Anolis OS update for doxygen
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Multicluster GlobalHub 1.3
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Service Interconnect
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- Fedora 32 update for drupal8
- Fedora 32 update for drupal7
- Fedora 31 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora 33 update for drupal7
- IBM CICS TX Advanced update for jQuery
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in OpenShift Logging 5.9
- Juniper Secure Analytics update for third-party components
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in Dell Storage Manager
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.16
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Service Interconnect 1
- Multiple vulnerabilities in Submariner 0.17
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Ubuntu update for jquery
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Ubuntu update for drupal7
- Cross-site scripting in Schneider Electric System Monitor Application
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in IBM DataStax Hyper-Converged Database