Cross-site scripting in jQuery - CVE-2011-4969

 

Cross-site scripting in jQuery - CVE-2011-4969

Published: August 15, 2016 / Updated: September 14, 2017


Vulnerability identifier: #VU313
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2011-4969
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to improper filtering of HTML code from user-supplied input before displaying the input. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user’s browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

jQuery
Netcool Operations Insight
QRadar User Behavior Analytics
Juniper Secure Analytics (JSA)
IBM Aspera Console
User Entity Behavior Analytics
IBM Storage Scale System
IBM Qradar SIEM
Ubuntu

How to mitigate CVE-2011-4969

Update to version 1.6.3.

Netcool Operations Insight - update to 1.6.15
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Aspera Console - update to 3.4.5 PL1
QRadar User Behavior Analytics - update to 4.1.9
User Entity Behavior Analytics - update to 5.0.2
IBM Storage Scale System - addressed in versions 5.2.0.0, 6.1.9.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Ubuntu - addressed in versions 10.04, 11.10

External References

Related Security Bulletins