Cross-site scripting in jQuery UI - CVE-2022-31160

 

Cross-site scripting in jQuery UI - CVE-2022-31160

Published: July 27, 2022


Vulnerability identifier: #VU65834
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-31160
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If .checkboxradio( "refresh" ) is called on such a widget and the initial HTML contains encoded HTML entities, they will erroneously get decoded and executed. A remote attacker can execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

jQuery UI
Request Tracker
Nautobot
IBM Data Risk Manager
Moodle
Oracle Financial Services Revenue Management and Billing
Oracle Hospitality Simphony
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
Oracle BI Publisher
Oracle Siebel CRM
User Entity Behavior Analytics
Cognos Dashboards on Cloud Pak for Data
IBM Engineering Lifecycle Optimization - Publishing
SecureTransport
Fedora
Ubuntu
IBM Tivoli Netcool Impact
WebSphere eXtreme Scale
Netcool Operations Insight
IBM Aspera Orchestrator
QRadar User Behavior Analytics
IBM Sterling B2B Integrator
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM Security Verify Governance
IBM Robotic Process Automation
IBM Qradar SIEM
Zoho ManageEngine OpManager
IBM Cognos Command Center
MySQL Enterprise Monitor
IBM InfoSphere Information Server
JD Edwards EnterpriseOne Tools
Primavera Unifier
Oracle Communications Billing and Revenue Management
Oracle WebLogic Server
Oracle Retail Customer Management and Segmentation Foundation
node-jquery-ui (Ubuntu package)
libjs-jquery-ui (Ubuntu package)
js-jquery-ui
Engineering Lifecycle Management

How to mitigate CVE-2022-31160

Install updates from vendor's website.

jQuery UI - update to 1.13.2
Request Tracker - update to 5.0.4
Nautobot - addressed in versions 1.6.18, 2.2.1
IBM Data Risk Manager - update to 2.0.6.15
Moodle - addressed in versions 3.9.23, 3.11.16
SecureTransport - update to 5.5-20221027
IBM Tivoli Netcool Impact - update to 7.1.0.32
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
WebSphere eXtreme Scale - update to 8.6.1.6 PH70967
JD Edwards EnterpriseOne Tools - update to 9.2.8.2
Zoho ManageEngine OpManager - update to 12.7 127103
Oracle Siebel CRM - update to 23.6
node-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
libjs-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
Netcool Operations Insight - update to 1.6.11
js-jquery-ui - addressed in versions 1.13.2-1.el7, 1.13.2-1.el8, 1.13.2-1.el9, 1.13.2-1.fc35, 1.13.2-1.fc36, 1.13.2-1.fc37
IBM Aspera Orchestrator - update to 4.0.1.2b9681
QRadar User Behavior Analytics - update to 4.1.12
User Entity Behavior Analytics - update to 5.0.2
Cognos Dashboards on Cloud Pak for Data - update to 5.1
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.30, 7.6.1.3.0.5
Maximo Manage Application in IBM Maximo Application Suite - update to 8.4.7
IBM Security Verify Governance - update to 10.0.2.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Robotic Process Automation - update to 21.0.4

External References

Related Security Bulletins