DNA View

CVE-2016-7103

Medium
Low Medium High Critical
6.1
CVSS Score
Published: Mar 15, 2017
Last Modified: Apr 20, 2025

Vulnerability Description

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
C
Confidentiality
L
Integrity
L
Availability
N

Known Affected Software

72 configuration(s) from 7 vendor(s)

debian_linux
Version:
9.0
CPE:
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
fedora
Version:
30
CPE:
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
fedora
Version:
35
CPE:
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
fedora
Version:
36
CPE:
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
jquery_ui
Version:
1.11.3
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.11.3:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.11.1
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.11.1:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.10.2
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.10.2:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.11.0
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.11.0:rc1:*:*:*:jquery:*:*
jquery_ui
Version:
1.10.1
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.10.1:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.11.2
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.11.2:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.11.4
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.11.4:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.10.0
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.10.0:beta1:*:*:*:jquery:*:*
jquery_ui
Version:
1.10.4
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.10.4:*:*:*:*:jquery:*:*
jquery_ui
Version:
1.10.3
CPE:
cpe:2.3:a:jqueryui:jquery_ui:1.10.3:*:*:*:*:jquery:*:*
junos
Version:
21.2
CPE:
cpe:2.3:o:juniper:junos:21.2:r3-s8:*:*:*:*:*:*
snapcenter
Version:
-
CPE:
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
application_express
Version:
4.0
CPE:
cpe:2.3:a:oracle:application_express:4.0:*:*:*:*:*:*:*
application_express
Version:
3.0
CPE:
cpe:2.3:a:oracle:application_express:3.0:*:*:*:*:*:*:*
primavera_unifier
Version:
18.3
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.3:*:*:*:*:*:*:*
primavera_unifier
Version:
17.10
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.10:*:*:*:*:*:*:*
primavera_unifier
Version:
18.7
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.7:*:*:*:*:*:*:*
application_express
Version:
5.1.4.00.08
CPE:
cpe:2.3:a:oracle:application_express:5.1.4.00.08:*:*:*:*:*:*:*
primavera_unifier
Version:
17.12.4
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.12.4:*:*:*:*:*:*:*
primavera_unifier
Version:
16.0
CPE:
cpe:2.3:a:oracle:primavera_unifier:16.0:*:*:*:*:*:*:*
application_express
Version:
3.2
CPE:
cpe:2.3:a:oracle:application_express:3.2:*:*:*:*:*:*:*
primavera_unifier
Version:
17.9
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.9:*:*:*:*:*:*:*
business_intelligence
Version:
12.2.1.3.0
CPE:
cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
primavera_unifier
Version:
16.2
CPE:
cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
oss_support_tools
Version:
2.12.42
CPE:
cpe:2.3:a:oracle:oss_support_tools:2.12.42:*:*:*:*:*:*:*
application_express
Version:
5.1.2.00.09
CPE:
cpe:2.3:a:oracle:application_express:5.1.2.00.09:*:*:*:*:*:*:*
primavera_unifier
Version:
17.1
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.1:*:*:*:*:*:*:*
application_express
Version:
18.2
CPE:
cpe:2.3:a:oracle:application_express:18.2:*:*:*:*:*:*:*
primavera_unifier
Version:
17.11
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.11:*:*:*:*:*:*:*
primavera_unifier
Version:
17.5
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.5:*:*:*:*:*:*:*
primavera_unifier
Version:
18.6
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.6:*:*:*:*:*:*:*
primavera_unifier
Version:
18.0
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.0:*:*:*:*:*:*:*
business_intelligence
Version:
12.2.1.4.0
CPE:
cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
application_express
Version:
5.0
CPE:
cpe:2.3:a:oracle:application_express:5.0:*:*:*:*:*:*:*
application_express
Version:
4.1
CPE:
cpe:2.3:a:oracle:application_express:4.1:*:*:*:*:*:*:*
primavera_unifier
Version:
18.8.4
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.8.4:*:*:*:*:*:*:*
application_express
Version:
5.1.3
CPE:
cpe:2.3:a:oracle:application_express:5.1.3:*:*:*:*:*:*:*
primavera_unifier
Version:
17.0
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.0:*:*:*:*:*:*:*
primavera_unifier
Version:
17.6
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.6:*:*:*:*:*:*:*
primavera_unifier
Version:
17.8
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.8:*:*:*:*:*:*:*
primavera_unifier
Version:
18.4
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.4:*:*:*:*:*:*:*
weblogic_server
Version:
10.3.6.0.0
CPE:
cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
primavera_unifier
Version:
18.2
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.2:*:*:*:*:*:*:*
application_express
Version:
5.1.0
CPE:
cpe:2.3:a:oracle:application_express:5.1.0:*:*:*:*:*:*:*
primavera_unifier
Version:
17.7
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.7:*:*:*:*:*:*:*
primavera_unifier
Version:
17.4
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.4:*:*:*:*:*:*:*
application_express
Version:
4.2
CPE:
cpe:2.3:a:oracle:application_express:4.2:*:*:*:*:*:*:*
primavera_unifier
Version:
18.8.3
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.8.3:*:*:*:*:*:*:*
primavera_unifier
Version:
18.5
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.5:*:*:*:*:*:*:*
application_express
Version:
5.1.3.00.05
CPE:
cpe:2.3:a:oracle:application_express:5.1.3.00.05:*:*:*:*:*:*:*
application_express
Version:
5.1.1
CPE:
cpe:2.3:a:oracle:application_express:5.1.1:*:*:*:*:*:*:*
application_express
Version:
5.1.2
CPE:
cpe:2.3:a:oracle:application_express:5.1.2:*:*:*:*:*:*:*
primavera_unifier
Version:
18.8.2
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.8.2:*:*:*:*:*:*:*
application_express
Version:
5.1.4
CPE:
cpe:2.3:a:oracle:application_express:5.1.4:*:*:*:*:*:*:*
primavera_unifier
Version:
17.3
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.3:*:*:*:*:*:*:*
hospitality_cruise_fleet_management
Version:
9.0.11
CPE:
cpe:2.3:a:oracle:hospitality_cruise_fleet_management:9.0.11:*:*:*:*:*:*:*
primavera_unifier
Version:
17.12
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.12:*:*:*:*:*:*:*
weblogic_server
Version:
12.1.3.0.0
CPE:
cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*
primavera_unifier
Version:
16.1
CPE:
cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
primavera_unifier
Version:
18.1
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.1:*:*:*:*:*:*:*
primavera_unifier
Version:
17.2
CPE:
cpe:2.3:a:oracle:primavera_unifier:17.2:*:*:*:*:*:*:*
weblogic_server
Version:
12.2.1.3.0
CPE:
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
application_express
Version:
5.0.4
CPE:
cpe:2.3:a:oracle:application_express:5.0.4:*:*:*:*:*:*:*
application_express
Version:
3.1
CPE:
cpe:2.3:a:oracle:application_express:3.1:*:*:*:*:*:*:*
primavera_unifier
Version:
18.8
CPE:
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
openstack
Version:
9
CPE:
cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*
openstack
Version:
8
CPE:
cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*
openstack
Version:
7.0
CPE:
cpe:2.3:a:redhat:openstack:7.0:*:*:*:*:*:*:*
This vulnerability affects 72 software configuration(s). Ensure you patch all affected systems.

References & Resources

Severity Details

6.1
out of 10.0
Medium

Weakness Type (CWE)

CWE-79 Top 25 #1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Exploit Likelihood
High
Typical Severity
Medium
OWASP Top 10
A03:2021-Injection
Abstraction Level
Base

Key Information

Published Date
March 15, 2017