CVE-2020-11023
CVE Published | 2020-04-29 |
---|---|
Related CWE(s) | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Related Vendor(s) | netapp, fedoraproject, jquery, tenable, drupal, oracle, debian |
Related Product(s) | h500e_firmware, debian_linux, drupal, communications_session_route_manager, snap_creator_framework, primavera_gateway, storagetek_tape_analytics_sw_tool, healthcare_translational_research, business_intelligence, communications_analytics, h410s_firmware, banking_enterprise_collections, oncommand_insight, jquery, application_testing_suite, communications_interactive_session_recorder, log_correlation_engine, oss_support_tools, communications_eagle_application_processor, jd_edwards_enterpriseone_tools, h300s_firmware, communications_services_gatekeeper, application_express, health_sciences_inform, communications_operations_monitor, snapcenter_server, communications_session_report_manager, oncommand_system_manager, communications_element_manager, h410c_firmware, max_data, jd_edwards_enterpriseone_orchestrator, hyperion_financial_reporting, fedora, h700s_firmware, banking_platform, siebel_mobile, financial_services_revenue_management_and_billing_analytics, h500s_firmware, financial_services_regulatory_reporting_for_de_nederlandsche_bank, webcenter_sites, storagetek_acsls, weblogic_server, peoplesoft_enterprise_human_capital_management_resources, h700e_firmware, rest_data_services, h300e_firmware |
Exploitation Reported (CISA KEV) | 2025-01-23 |
CVSS 3 Base Score | 6.1 (MEDIUM) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph