Cross-site scripting in jQuery UI - CVE-2021-41184

 

Cross-site scripting in jQuery UI - CVE-2021-41184

Published: November 20, 2021 / Updated: October 2, 2024


Vulnerability identifier: #VU58271
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-41184
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of values passed to the `of` option. A remote attacker can execute arbitrary JavaScript code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

jQuery UI
Tenable.sc
Oracle Utilities Network Management System
Oracle Banking Platform
Oracle Communications Operations Monitor
IBM Cloud Pak for Watson AIOps
Oracle Financial Services Analytical Applications Infrastructure
Oracle Policy Automation
Oracle Retail Returns Management
Oracle Retail Back Office
Oracle Retail Central Office
IBM Aspera Shares
IBM Engineering Lifecycle Optimization - Publishing
Moodle
Oracle Utilities Application Framework
Oracle Health Sciences InForm
Oracle Financial Services Balance Computation Engine
Oracle Fusion Middleware MapViewer
Oracle Business Process Management Suite
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
Nessus Network Monitor
JD Edwards EnterpriseOne Tools
Enterprise Manager for Oracle Database
Primavera Unifier
SecureTransport
Oracle Communications Interactive Session Recorder
Fedora
Ubuntu
IBM Tivoli Netcool Impact
Oracle Financial Services Analytical Applications Reconciliation Framework
Oracle Financial Services Data Integration Hub
Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management
Oracle Financial Services Liquidity Risk Measurement and Management
Oracle Financial Services Asset Liability Management
Oracle Financial Services Enterprise Financial Performance Analytics
Oracle Financial Services Institutional Performance Analytics
Oracle Financial Services Loan Loss Forecasting and Provisioning
Oracle Financial Services Profitability Management
Oracle Financial Services Retail Performance Analytics
Oracle Financial Services Balance Sheet Planning
Oracle Financial Services Data Governance for US Regulatory Reporting
WebSphere eXtreme Scale
Tenable Nessus
Oracle Communications EAGLE Element Management System
Netcool Operations Insight
IBM Aspera Orchestrator
QRadar User Behavior Analytics
IBM Sterling B2B Integrator
IBM Security Verify Governance
MySQL Enterprise Monitor
IBM InfoSphere Information Analyzer
Enterprise Manager for Exadata
Oracle GoldenGate
Big Data Spatial and Graph
Oracle Financial Services Funds Transfer Pricing
Oracle Hospitality Suite8
Oracle Hospitality Inventory Management
Oracle Hospitality Simphony
Splunk Enterprise
IBM Security SOAR
Oracle SD-WAN Aware
Oracle Agile PLM Framework
SAPUI5
Engineering Lifecycle Management
Oracle REST Data Services
Oracle Commerce Guided Search
Oracle WebLogic Server
Oracle Hospitality Materials Control
Oracle Application Express
node-jquery-ui (Ubuntu package)
libjs-jquery-ui (Ubuntu package)
js-jquery-ui
drupal7
IBM API Connect

How to mitigate CVE-2021-41184

Install updates from vendor's website.

jQuery UI - update to 1.13.0
Tenable.sc - update to 5.21.0
Moodle - addressed in versions 3.9.23, 3.11.16
Nessus Network Monitor - update to 6.0.1
SecureTransport - update to 5.5-20220428
Oracle Health Sciences InForm - addressed in versions 6.3.1.3, 7.0.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.32
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH70967
Tenable Nessus - update to 10.2.0
IBM InfoSphere Information Analyzer - addressed in versions 11.7.1.0, 11.7.1.3
Oracle Application Express - update to 22.1.1
Big Data Spatial and Graph - update to 23.1
node-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
libjs-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
Netcool Operations Insight - update to 1.6.11
IBM Aspera Shares - update to 1.10.0 PL1
js-jquery-ui - addressed in versions 1.13.0-1.el8, 1.13.0-1.fc33, 1.13.0-1.fc34, 1.13.0-1.fc35
IBM Aspera Orchestrator - update to 4.0.1.2b9681
QRadar User Behavior Analytics - update to 4.1.8
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37
IBM API Connect - addressed in versions 10.0.1.8, 10.0.5.1
IBM Security Verify Governance - update to 10.0.2.0.1
Oracle REST Data Services - update to 22.1.1
IBM Security SOAR - update to 44.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins