CVE-2016-7103

medium
Published 2016-08-27 ยท Modified 2024-03-11
CVSS v3
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.1

Description

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Predictions

Exploit likelihood
71%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed1.12.1+dfsg-1
debian debianbullseyefixed1.12.1+dfsg-1
debian debianforkyfixed1.12.1+dfsg-1
debian debiansidfixed1.12.1+dfsg-1
debian debiantrixiefixed1.12.1+dfsg-1
fedora fedora30affected
fedora fedora35affected
fedora fedora36affected
debian debian9.0affected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsjquery-ui-rails<>= 6.0.0>= 6.0.0
npm npmjquery-ui<1.12.01.12.0
ruby RubyGemsjquery-ui-rails<6.0.06.0.0
java Mavenorg.webjars.npm:jquery-ui<1.12.01.12.0
nuget NuGetjQuery.UI.Combined<1.12.01.12.0

Application impact

VendorProductVersionsFixed
jqueryuijquery_ui{"startIncluding":"1.10.0","endIncluding":"1.11.4"}
oracle oracleapplication_express{"endExcluding":"19.1"}19.1
oracle oraclebusiness_intelligence12.2.1.3.0
oracle oraclebusiness_intelligence12.2.1.4.0
oracle oraclehospitality_cruise_fleet_management9.0.11
oracle oracleoss_support_tools{"endExcluding":"2.12.42"}2.12.42
oracle oracleoss_support_tools2.12.42
oracle oracleprimavera_unifier{"startIncluding":"16.0","endIncluding":"16.2"}
oracle oraclesiebel_ui_framework{"endIncluding":"21.2"}
oracle oracleweblogic_server10.3.6.0.0
oracle oracleweblogic_server12.1.3.0.0
oracle oracleweblogic_server12.2.1.3.0
netappsnapcenter-
redhat redhatopenstack7.0
redhat redhatopenstack8
redhat redhatopenstack9

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.