{"id":"CVE-2019-11358","details":"jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.","aliases":["DRUPAL-CORE-2019-006","GHSA-6c3j-c64m-qhgq","SNYK-JS-JQUERY-174006"],"modified":"2026-05-28T04:04:52.499801280Z","published":"2019-04-20T00:29:00.247Z","related":["ALSA-2020:4670","openSUSE-SU-2019:1839-1","openSUSE-SU-2019:1872-1","openSUSE-SU-2024:0231-1","openSUSE-SU-2024:11205-1","openSUSE-SU-2024:11242-1","openSUSE-SU-2024:13887-1","openSUSE-SU-2024:14208-1","openSUSE-SU-2026:10005-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"netapp:oncommand_system_manager","source":"CPE_RANGE","cpes":["cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.0"},{"last_affected":"3.1.3"}]},{"vendor_product":"oracle:application_express","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"19.1"}]},{"vendor_product":"oracle:banking_enterprise_collections","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.8.0"}]},{"vendor_product":"oracle:banking_platform","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.4.0"},{"last_affected":"2.10.0"}]},{"vendor_product":"oracle:communications_eagle_application_processor","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:communications_eagle_application_processor:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"16.1.0"},{"last_affected":"16.4.0"}]},{"vendor_product":"oracle:communications_interactive_session_recorder","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.4"}]},{"vendor_product":"oracle:communications_operations_monitor","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:communications_operations_monitor:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.1"},{"last_affected":"4.3"}]},{"vendor_product":"oracle:financial_services_analytical_applications_infrastructure","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3.3"},{"last_affected":"7.3.5"},{"introduced":"8.0.2"},{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_analytical_applications_reconciliation_framework","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_asset_liability_management","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_asset_liability_management:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_basel_regulatory_capital_basic","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_data_foundation","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_data_foundation:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.8"}]},{"vendor_product":"oracle:financial_services_data_governance_for_us_regulatory_reporting","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_data_governance_for_us_regulatory_reporting:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.6"},{"last_affected":"8.0.9"}]},{"vendor_product":"oracle:financial_services_data_integration_hub","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_data_integration_hub:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.5"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_funds_transfer_pricing","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_hedge_management_and_ifrs_valuations","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_institutional_performance_analytics","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_loan_loss_forecasting_and_provisioning","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.2"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_price_creation_and_discovery","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_profitability_management","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_profitability_management:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_regulatory_reporting_for_us_federal_reserve","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_us_federal_reserve:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_retail_customer_analytics","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:financial_services_retail_customer_analytics:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.6"}]},{"vendor_product":"oracle:hospitality_simphony","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"19.1.0"},{"last_affected":"19.1.2"}]},{"vendor_product":"oracle:insurance_data_foundation","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:insurance_data_foundation:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.4"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:insurance_insbridge_rating_and_underwriting","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.0.0.0"},{"last_affected":"5.6.0.0"}]},{"vendor_product":"oracle:knowledge","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:knowledge:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.6.0"},{"last_affected":"8.6.3"}]},{"vendor_product":"oracle:policy_automation","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.2.0"},{"last_affected":"12.2.15"}]},{"vendor_product":"oracle:policy_automation_for_mobile_devices","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.2.0"},{"last_affected":"12.2.15"}]},{"vendor_product":"oracle:primavera_gateway","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"16.2.0"},{"last_affected":"16.2.11"},{"introduced":"17.12.0"},{"last_affected":"17.12.7"},{"introduced":"18.8.0"},{"last_affected":"18.8.9"},{"introduced":"19.12.0"},{"last_affected":"19.12.4"}]},{"vendor_product":"oracle:primavera_unifier","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"17.7"},{"last_affected":"17.12"}]},{"vendor_product":"oracle:real-time_scheduler","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:real-time_scheduler:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0.1"},{"last_affected":"2.3.0.3"}]},{"vendor_product":"oracle:siebel_mobile_applications","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:siebel_mobile_applications:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"19.8"}]},{"vendor_product":"oracle:utilities_mobile_workforce_management","source":"CPE_RANGE","cpes":["cpe:2.3:a:oracle:utilities_mobile_workforce_management:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0.1"},{"last_affected":"2.3.0.3"}]},{"vendor_product":"debian:debian_linux","source":"CPE_STRING","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0"},{"last_affected":"9.0"},{"last_affected":"10.0"}]},{"vendor_product":"fedoraproject:fedora","source":"CPE_STRING","cpes":["cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"28"},{"last_affected":"29"},{"last_affected":"30"}]},{"vendor_product":"juniper:junos","source":"CPE_STRING","cpes":["cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"21.2-NA"}]},{"vendor_product":"opensuse:backports_sle","source":"CPE_STRING","cpes":["cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"15.0-sp1"}]},{"vendor_product":"opensuse:leap","source":"CPE_STRING","cpes":["cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"15.1"}]},{"vendor_product":"oracle:agile_product_lifecycle_management_for_process","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"6.1"},{"last_affected":"6.2.0.0"},{"last_affected":"6.2.1.0"},{"last_affected":"6.2.2.0"},{"last_affected":"6.2.3.0"}]},{"vendor_product":"oracle:application_service_level_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:application_service_level_management:13.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_service_level_management:13.3.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"13.2.0.0"},{"last_affected":"13.3.0.0"}]},{"vendor_product":"oracle:application_testing_suite","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.3:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.5.0.3"},{"last_affected":"13.1.0.1"},{"last_affected":"13.2"},{"last_affected":"13.2.0.1"},{"last_affected":"13.3"},{"last_affected":"13.3.0.1"}]},{"vendor_product":"oracle:banking_digital_experience","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"18.1"},{"last_affected":"18.2"},{"last_affected":"18.3"},{"last_affected":"19.1"},{"last_affected":"19.2"},{"last_affected":"20.1"}]},{"vendor_product":"oracle:bi_publisher","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:bi_publisher:5.5.0.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"5.5.0.0.0"},{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"oracle:big_data_discovery","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:big_data_discovery:1.6:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.6"}]},{"vendor_product":"oracle:business_process_management_suite","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"oracle:communications_analytics","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_analytics:12.1.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.1.1"}]},{"vendor_product":"oracle:communications_application_session_controller","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_application_session_controller:3.8m0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"3.8m0"}]},{"vendor_product":"oracle:communications_billing_and_revenue_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.5"},{"last_affected":"7.5.0.23.0"},{"last_affected":"12.0"},{"last_affected":"12.0.0.3.0"}]},{"vendor_product":"oracle:communications_diameter_signaling_router","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.0"},{"last_affected":"8.1"},{"last_affected":"8.2"},{"last_affected":"8.2.1"}]},{"vendor_product":"oracle:communications_element_manager","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.1"},{"last_affected":"8.2.0"},{"last_affected":"8.2.1"}]},{"vendor_product":"oracle:communications_operations_monitor","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_operations_monitor:4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_operations_monitor:4.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"3.4"},{"last_affected":"4.0"},{"last_affected":"4.1.0"}]},{"vendor_product":"oracle:communications_services_gatekeeper","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.0"}]},{"vendor_product":"oracle:communications_session_report_manager","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.1"},{"last_affected":"8.2.0"},{"last_affected":"8.2.1"}]},{"vendor_product":"oracle:communications_session_route_manager","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.1"},{"last_affected":"8.2.0"},{"last_affected":"8.2.1"}]},{"vendor_product":"oracle:communications_unified_inventory_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_unified_inventory_management:7.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.3"},{"last_affected":"7.4.0"}]},{"vendor_product":"oracle:communications_webrtc_session_controller","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.2"}]},{"vendor_product":"oracle:diagnostic_assistant","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:diagnostic_assistant:2.12.36:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2.12.36"}]},{"vendor_product":"oracle:enterprise_manager_ops_center","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.3.3"},{"last_affected":"12.4.0"},{"last_affected":"12.4.0.0"}]},{"vendor_product":"oracle:enterprise_session_border_controller","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:enterprise_session_border_controller:8.4:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.4"}]},{"vendor_product":"oracle:financial_services_analytical_applications_reconciliation_framework","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_analytical_applications_reconciliation_framework:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_asset_liability_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_asset_liability_management:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_balance_sheet_planning","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.8:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.8"}]},{"vendor_product":"oracle:financial_services_basel_regulatory_capital_basic","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_basic:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_basel_regulatory_capital_internal_ratings_based_approach:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_data_integration_hub","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_data_integration_hub:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_enterprise_financial_performance_analytics","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_enterprise_financial_performance_analytics:8.0.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_enterprise_financial_performance_analytics:8.0.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.6"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_funds_transfer_pricing","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_hedge_management_and_ifrs_valuations","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_institutional_performance_analytics","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_liquidity_risk_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.5.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_management:8.0.6:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.0.1.0"},{"last_affected":"8.0.2"},{"last_affected":"8.0.4.0.0"},{"last_affected":"8.0.5.0.0"},{"last_affected":"8.0.6"}]},{"vendor_product":"oracle:financial_services_liquidity_risk_measurement_and_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.7:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_liquidity_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.7"},{"last_affected":"8.0.8"},{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_loan_loss_forecasting_and_provisioning","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_market_risk_measurement_and_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.5"},{"last_affected":"8.0.6"},{"last_affected":"8.0.8"}]},{"vendor_product":"oracle:financial_services_profitability_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_profitability_management:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:financial_services_regulatory_reporting_for_de_nederlandsche_bank","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_de_nederlandsche_bank:8.0.4:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.4"}]},{"vendor_product":"oracle:financial_services_regulatory_reporting_for_european_banking_authority","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:8.0.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_european_banking_authority:8.0.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.6"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_retail_performance_analytics","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_retail_performance_analytics:8.0.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_retail_performance_analytics:8.0.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.6"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:financial_services_revenue_management_and_billing","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.4.0.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2.4.0.0"},{"last_affected":"2.4.0.1"}]},{"vendor_product":"oracle:fusion_middleware_mapviewer","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.2.1.3.0"}]},{"vendor_product":"oracle:healthcare_foundation","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:healthcare_foundation:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_foundation:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_foundation:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_foundation:7.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"7.1.1"},{"last_affected":"7.2.0"},{"last_affected":"7.2.2"},{"last_affected":"7.3.0"}]},{"vendor_product":"oracle:healthcare_translational_research","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:healthcare_translational_research:3.1.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_translational_research:3.2.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_translational_research:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_translational_research:3.3.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:healthcare_translational_research:3.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"3.1.0"},{"last_affected":"3.2.1"},{"last_affected":"3.3.1"},{"last_affected":"3.3.2"},{"last_affected":"3.4.0"}]},{"vendor_product":"oracle:hospitality_guest_access","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"4.2.0"},{"last_affected":"4.2.1"}]},{"vendor_product":"oracle:hospitality_materials_control","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"18.1"}]},{"vendor_product":"oracle:hospitality_simphony","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:hospitality_simphony:18.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_simphony:18.2:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"18.1"},{"last_affected":"18.2"}]},{"vendor_product":"oracle:identity_manager","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:identity_manager:12.2.1.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.2.1.3.0"}]},{"vendor_product":"oracle:insurance_accounting_analyzer","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:insurance_accounting_analyzer:8.0.9:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.9"}]},{"vendor_product":"oracle:insurance_allocation_manager_for_enterprise_profitability","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.0.8:*:*:*:*:*:*:*","cpe:2.3:a:oracle:insurance_allocation_manager_for_enterprise_profitability:8.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.8"},{"last_affected":"8.1.0"}]},{"vendor_product":"oracle:insurance_ifrs_17_analyzer","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:insurance_ifrs_17_analyzer:8.0.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:insurance_ifrs_17_analyzer:8.0.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.6"},{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:insurance_insbridge_rating_and_underwriting","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"5.6.1.0"}]},{"vendor_product":"oracle:insurance_performance_insight","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:insurance_performance_insight:8.0.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0.7"}]},{"vendor_product":"oracle:jd_edwards_enterpriseone_tools","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"9.2"}]},{"vendor_product":"oracle:jdeveloper","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"11.1.1.9.0"},{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}]},{"vendor_product":"oracle:jdeveloper_and_adf","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:jdeveloper_and_adf:11.1.1.9.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:jdeveloper_and_adf:12.1.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:jdeveloper_and_adf:12.2.1.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"11.1.1.9.0"},{"last_affected":"12.1.3.0.0"},{"last_affected":"12.2.1.3.0"}]},{"vendor_product":"oracle:peoplesoft_enterprise_peopletools","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.55"},{"last_affected":"8.56"},{"last_affected":"8.57"},{"last_affected":"8.58"}]},{"vendor_product":"oracle:policy_automation","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:policy_automation:10.4.7:*:*:*:*:*:*:*","cpe:2.3:a:oracle:policy_automation:12.1.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:policy_automation:12.1.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"10.4.7"},{"last_affected":"12.1.0"},{"last_affected":"12.1.1"}]},{"vendor_product":"oracle:policy_automation_connector_for_siebel","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"10.4.6"}]},{"vendor_product":"oracle:primavera_gateway","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:primavera_gateway:15.2.18:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"15.2.18"}]},{"vendor_product":"oracle:primavera_unifier","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"16.1"},{"last_affected":"16.2"},{"last_affected":"18.8"}]},{"vendor_product":"oracle:rest_data_services","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:*","cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:*","cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:*","cpe:2.3:a:oracle:rest_data_services:18c:*:*:*:-:*:*:*","cpe:2.3:a:oracle:rest_data_services:19c:*:*:*:-:*:*:*"],"extracted_events":[{"last_affected":"11.2.0.4"},{"last_affected":"12.1.0.2"},{"last_affected":"12.2.0.1"},{"last_affected":"18c"},{"last_affected":"19c"}]},{"vendor_product":"oracle:retail_back_office","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"14.0"},{"last_affected":"14.1"}]},{"vendor_product":"oracle:retail_central_office","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_central_office:14.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"14.0"},{"last_affected":"14.1"}]},{"vendor_product":"oracle:retail_customer_insights","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_customer_insights:16.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"15.0"},{"last_affected":"16.0"}]},{"vendor_product":"oracle:retail_customer_management_and_segmentation_foundation","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"18.0"},{"last_affected":"19.0"}]},{"vendor_product":"oracle:retail_point-of-service","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_point-of-service:14.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"14.0"},{"last_affected":"14.1"}]},{"vendor_product":"oracle:retail_returns_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"14.0"},{"last_affected":"14.1"}]},{"vendor_product":"oracle:service_bus","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:service_bus:11.1.1.9.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:service_bus:12.1.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:service_bus:12.2.1.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"11.1.1.9.0"},{"last_affected":"12.1.3.0.0"},{"last_affected":"12.2.1.3.0"}]},{"vendor_product":"oracle:siebel_ui_framework","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:siebel_ui_framework:20.8:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"20.8"}]},{"vendor_product":"oracle:storagetek_tape_analytics_sw_tool","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2.3.0"}]},{"vendor_product":"oracle:system_utilities","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:system_utilities:19.1:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"19.1"}]},{"vendor_product":"oracle:tape_library_acsls","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:tape_library_acsls:8.5.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:tape_library_acsls:8.5:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.5"},{"last_affected":"8.5.1"}]},{"vendor_product":"oracle:transportation_management","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:transportation_management:1.4.3:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.4.3"}]},{"vendor_product":"oracle:webcenter_sites","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"12.2.1.3.0"}]},{"vendor_product":"oracle:weblogic_server","source":"CPE_STRING","cpes":["cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"10.3.6.0.0"},{"last_affected":"12.1.3.0.0"},{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"},{"last_affected":"14.1.1.0.0"}]},{"vendor_product":"redhat:cloudforms","source":"CPE_STRING","cpes":["cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"4.7"}]},{"vendor_product":"redhat:virtualization_manager","source":"CPE_STRING","cpes":["cpe:2.3:a:redhat:virtualization_manager:4.3:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"4.3"}]}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/May/10"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/108023"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:1570"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2587"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3023"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3024"},{"type":"ADVISORY","url":"https://backdropcms.org/security/backdrop-sa-core-2019-009"},{"type":"ADVISORY","url":"https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/"},{"type":"ADVISORY","url":"https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5/"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Apr/32"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190919-0001/"},{"type":"ADVISORY","url":"https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4434"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4460"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_19_19"},{"type":"ADVISORY","url":"https://www.tenable.com/security/tns-2019-08"},{"type":"ADVISORY","url":"https://www.tenable.com/security/tns-2020-02"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache.org%3E"},{"type":"REPORT","url":"https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E"},{"type":"REPORT","url":"https://seclists.org/bugtraq/2019/Jun/12"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2019/May/11"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2019/May/13"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2019/06/03/2"},{"type":"FIX","url":"https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b"},{"type":"FIX","url":"https://github.com/jquery/jquery/pull/4333"},{"type":"FIX","url":"https://seclists.org/bugtraq/2019/May/18"},{"type":"FIX","url":"https://www.drupal.org/sa-core-2019-006"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"FIX","url":"https://www.privacy-wise.com/mitigating-cve-2019-11358-in-old-versions-of-jquery/"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-JQUERY-174006"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/backdrop/backdrop","events":[{"introduced":"963141d57d9ba861216fa85bf8a135f65d2c06be"},{"fixed":"17198299114cf7c5c88a1bdf597a74734751687d"},{"introduced":"b7f9a6908911617be8f83ea1d7daaa3be2453874"},{"fixed":"8e7a1b9546d32ac84f7bfaaaf3ee2439ba7b0c1a"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"1.11.0"},{"fixed":"1.11.9"},{"introduced":"1.12.0"},{"fixed":"1.12.6"}],"cpe":"cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:*"}}],"versions":["1.11.8","1.12.5","1.11.7","1.12.4","1.12.3","1.11.6","1.12.2","1.11.5","1.12.1","1.12.0","1.11.4","1.11.3","1.11.2","1.11.1","1.11.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11358.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/drupal/drupal","events":[{"introduced":"497914920385b7016ac9c9367e0198530787adf2"},{"fixed":"9735baff3afe061f98e568c1d1f83d56f3a0212a"},{"introduced":"b73ab73d39dca97a12513e8a9e4f4da4b0676f5f"},{"fixed":"c5bc3922f27c93ab3669428a504212adb801400f"},{"introduced":"9b04d294324d9c76be4b596de4316cb8804e8223"},{"fixed":"91ded4b7776e05ee9633bdc1c458b41c718133e0"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"7.0"},{"fixed":"7.66"},{"introduced":"8.5.0"},{"fixed":"8.5.15"},{"introduced":"8.6.0"},{"fixed":"8.6.15"}],"cpe":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*"}}],"versions":["7.65","8.5.14","8.6.14","7.64","8.5.13","8.6.12","8.5.12","8.6.11","8.6.9","8.6.8","7.61","8.6.5","8.6.4","8.6.3","8.6.1","8.5.7","8.6.0","8.5.5","8.5.4","8.5.0","7.56","7.55","7.54","7.51","7.50","7.43","7.42","7.40","7.37","7.36","7.33","7.30","7.28","7.25","7.23","7.22","7.17","7.15","7.14","7.12","7.10","7.9","7.8","7.7","7.6","7.4","7.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11358.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/joomla/joomla-cms","events":[{"introduced":"c1acb7e6973bd549fe35a02659fe851ff1a37dfe"},{"last_affected":"bbdf775fbee26d275ce60ea466b778e4694210a1"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.9.4"}],"cpe":"cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*"}}],"versions":["3.9.4","3.9.3","3.9.2-rc","3.9.1","3.9.0","3.9.0-rc","3.9.0-beta4","3.9.4-rc","3.8.11","3.9.3-rc","3.9.2","3.8.8","3.9.1-rc","3.9.0-rc2","3.8.7","3.8.12","3.9.0-beta3","3.9.0-beta2","3.9.0-beta","3.8.12-rc","3.8.11-rc","3.8.6","3.8.10","3.8.9","3.8.4","3.8.9-rc","issues-241-257","3.8.8-rc","3.8.7-rc","3.8.6-rc1","3.8.3","3.8.3-rc","3.8.5","3.8.5-rc","3.8.4-rc2","3.8.4-rc","3.8.2","3.8.1","3.8.0","3.8.2-rc","3.8.1-rc","3.8.0-rc1","3.8.0-beta2","3.8.0-beta4","3.8.0-beta1","3.8.0-beta3","3.7.4-rc1","3.7.4-beta1","3.7.3","3.7.3-rc2","3.7.3-rc1","3.7.3-beta1","3.7.2","3.7.1","3.7.1-rc2","3.7.1-rc1","3.7.0","3.7.0-rc4","3.7.0-rc3","3.7.0-rc2","3.7.0-rc1","3.7.0-beta4","3.7.0-beta3","3.7.0-beta2","3.7.0-beta1","3.7.0-alpha1","3.6.3","3.6.3-rc3","3.6.3-rc2","3.6.3-rc1","3.6.2","3.6.1","3.6.1-rc2","3.6.1-rc1","3.6.0","3.6.0-rc2","3.6.0-rc","3.6.0-beta2","3.6.0-beta1","3.6.0-alpha","3.5.1","3.5.1-rc2","3.5.1-rc","3.5.0","3.5.0-rc4","3.5.0-rc2","3.5.0-rc","3.5.0-beta5","3.5.0-beta4","3.5.0-beta3","3.5.0-beta2","3.4.5","3.5.0-beta","3.4.4","3.4.4-rc2","3.4.4-rc","3.4.3","3.4.2","3.4.2-rc","3.4.1","3.4.1-rc2","3.4.1-rc","3.4.0","3.4.0-rc","3.4.0-beta3","3.4.0-beta2","3.4.0-beta1","3.2.4","3.3.0","3.2.3","3.2.2","3.2.1","3.2.0","3.1.5","3.2.0.rc","3.2.0.beta","3.2.0.alpha","3.1.1","3.0.3","3.1.0_beta5","3.1.0_beta4","3.1.0_beta3","3.1.0_beta2","3.1.0_beta1","3.0.1","3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11358.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/jquery/jquery","events":[{"introduced":"0"},{"fixed":"b7fc909edda2d8cf63d0eaffe9bd12f33e492ad3"},{"fixed":"753d591aea698e57d6db58c9f722cd0808619b1b"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"3.4.0"}],"cpe":"cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*"}}],"versions":["2.1.0-beta1","2.0.0-beta3","2.0.0b2","2.0.0b1","1.9.0b1","1.8rc1","1.8b2","1.8b1","1.7.2rc1","1.7.2b1","1.7.1rc1","1.7rc1","1.7b2","1.7b1","1.6.4rc1","1.6.3rc1","1.6.2rc1","1.6.1rc1","1.6rc1","1.6b1","1.5.2rc1","1.5.1rc1","1.5rc1","1.5b1","1.4.4rc3","1.4.4rc2","1.4.4rc1","1.4.3rc2","1.4.3rc1","1.4rc1","1.4a2","1.4a1","1.3.1rc1","1.3rc1","1.3b2","1.3b1","1.2.5","1.2.4","1.2.4b","1.2.4a","1.2.3b","1.2.3a","1.2.2","1.2.2b2","1.2.2b","1.2.1","1.2","1.1.4","1.1.3.1","1.1.3","1.1.3a","1.1.2","1.1.1","1.1","1.1b","1.1a","1.0.4","1.0.3","1.0.2","1.0.1","1.0","1.0a"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11358.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}