Cross-site scripting in jQuery UI - CVE-2016-7103
Published: December 10, 2016 / Updated: November 20, 2021
Vulnerability details
Vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability is caused by an input validation error in jQuery UI before 1.12.0. A remote authenticated attacker can trick the victim to follow a specially specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Modular Switchgear Monitoring (MSM)
OSS Support Tools
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
IBM Engineering Lifecycle Optimization - Publishing
Drupal
Red Hat OpenStack
Fedora
Ubuntu
Oracle WebLogic Server
Oracle Application Express
Siebel UI Framework
libjs-jquery-ui (Ubuntu package)
node-jquery-ui (Ubuntu package)
python-XStatic-jquery-ui
rubygem-jquery-ui-rails
drupal7
How to mitigate CVE-2016-7103
OSS Support Tools - update to 2.12.42
Drupal - update to 7.86
Oracle Application Express - update to 19.1
libjs-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
node-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
python-XStatic-jquery-ui - addressed in versions 1.12.0.1-1.el7, 1.12.0.1-1.fc24, 1.12.0.1-2.fc26, 1.12.0.1-4.fc25
rubygem-jquery-ui-rails - update to 6.0.1-1.fc30
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37
External References
Related Security Bulletins
- Cross-site scripting (XSS) in jQuery UI
- Red Hat update for python-XStatic-jquery-ui
- Red Hat update for python-XStatic-jquery-ui
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Siebel UI Framework
- Multiple vulnerabilities in Drupal third-party JS libraries
- Multiple vulnerabilities in OSS Support Tools
- Multiple vulnerabilities in Hitachi Energy MSM Product
- Multiple vulnerabilities in IBM Engineering Lifecycle Optimization - Publishing
- Ubuntu update for jqueryui
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Fedora 36 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora 37 update for drupal7
- Fedora 35 update for drupal7
- Fedora EPEL 7 update for python-XStatic-jquery-ui
- Fedora 24 update for python-XStatic-jquery-ui
- Fedora 26 update for python-XStatic-jquery-ui
- Fedora 25 update for python-XStatic-jquery-ui
- Fedora 30 update for rubygem-jquery-ui-rails
- Multiple vulnerabilities in Oracle WebLogic Server