CVE-2020-11022General(debian / agile_product_lifecycle_management_for_process)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agile_product_lifecycle_management_for_process
  • agile_product_supplier_collaboration_for_process
  • application_testing_suite
  • banking_digital_experience

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
agile_product_lifecycle_management_for_processagile_product_supplier_collaboration_for_processapplication_testing_suitebanking_digital_experienceblockchain_platformcommunications_application_session_controllercommunications_billing_and_revenue_managementcommunications_diameter_signaling_router_idih\communications_eagle_application_processorcommunications_services_gatekeeper

49 versions affected across 78 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-02: 1Mentions · 2026-05-30: 1Mentions · 2026-06-14: 1Technical Details · 2026-03-02: 1Technical Details · 2026-06-14: 103-0205-3006-14
Signal classification1 categories
General
3100.0%
Full discourse3 posts
  • sidharth@sidharthify
    General

    @ni5arga @thetirthparmar these are exposed to the following CVEs: CVE-2020-11023 CVE-2020-11022 CVE-2019-11358 CVE-2015-9251 CVE-2012-6708

    Post summary

    The tweet lists a set of CVEs but provides no additional details such as exploitation, patches, or technical specifics.

    31108904.5K
    510 followersView on X
  • Stormking@StormkingX2
    General

    @vhsliberal Ahem Btw isto é publico A versao que estao a usar no website publico ja acabou o supporte em 13 de maio 2017. Also para leres o cve que falava CVE-2019-11358 (Medium Severity - CVSS 6.1) CVE-2020-11022 & CVE-2020-11023 (Medium Severity - CVSS 6.9)

    Post summary

    The tweet lists two medium‑severity CVEs and notes that the public website version is out of support, but offers no details on exploitation, patches, or workarounds.

    1000026
    43 followersView on X
  • 🆉🅴🆁🅾 🅵🅸🅻🆃🅴🆁@Zerofilter_rw
    General

    Your mobile site is still running jQuery 3.2.1 + jQuery Mobile 1.5 in 2026 😂. Multiple public CVEs (CVE-2020-11022/11023 + prototype pollution chains) + AddThis data-* reflection = trivial persistent XSS → admin session theft → full backend access.

    Post summary

    The post highlights that a mobile site still runs outdated jQuery and references known CVEs, noting a persistent XSS that could lead to admin session theft.

    1000051
    444 followersView on X
CPE platform detail126 entries

126 of 126 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux9.0--
Appdrupaldrupal---
OSfedoraprojectfedora31--
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
Appjqueryjquery---
HWnetapph300e---
OSnetapph300e_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410c---
OSnetapph410c_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500e---
OSnetapph500e_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700e---
OSnetapph700e_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
Appnetappmax_data---
Appnetapponcommand_insight---
Appnetapponcommand_system_manager---
Appnetappsnap_creator_framework---
Appnetappsnapcenter---
OSopensuseleap15.1--
OSopensuseleap15.2--
Apporacleagile_product_lifecycle_management_for_process6.2.0.0--
Apporacleagile_product_supplier_collaboration_for_process6.2.0.0--
Apporacleapplication_testing_suite13.3.0.1--
Apporaclebanking_digital_experience---
Apporaclebanking_digital_experience18.1--
Apporaclebanking_digital_experience18.2--
Apporaclebanking_digital_experience18.3--
Apporaclebanking_digital_experience19.1--
Apporaclebanking_digital_experience19.2--
Apporaclebanking_digital_experience20.1--
Apporacleblockchain_platform---
Apporaclecommunications_application_session_controller3.8m0--
Apporaclecommunications_billing_and_revenue_management12.0.0.3.0--
Apporaclecommunications_billing_and_revenue_management7.5.0.23.0--
Apporaclecommunications_diameter_signaling_router_idih\---
Apporaclecommunications_eagle_application_processor---
Apporaclecommunications_services_gatekeeper7.0--
Apporaclecommunications_webrtc_session_controller7.2--
Apporacleenterprise_manager_ops_center12.4.0.0--
Apporacleenterprise_session_border_controller8.4--
Apporaclefinancial_services_analytical_applications_infrastructure---
Apporaclefinancial_services_analytical_applications_reconciliation_framework---
Apporaclefinancial_services_analytical_applications_reconciliation_framework8.1.0--
Apporaclefinancial_services_asset_liability_management8.0.6--
Apporaclefinancial_services_asset_liability_management8.0.7--
Apporaclefinancial_services_asset_liability_management8.1.0--
Apporaclefinancial_services_balance_sheet_planning8.0.8--
Apporaclefinancial_services_basel_regulatory_capital_basic---
Apporaclefinancial_services_basel_regulatory_capital_basic8.1.0--
Apporaclefinancial_services_basel_regulatory_capital_internal_ratings_based_approach---
Apporaclefinancial_services_basel_regulatory_capital_internal_ratings_based_approach8.1.0--
Apporaclefinancial_services_data_foundation---
Apporaclefinancial_services_data_governance_for_us_regulatory_reporting---
Apporaclefinancial_services_data_integration_hub8.0.6--
Apporaclefinancial_services_data_integration_hub8.0.7--
Apporaclefinancial_services_data_integration_hub8.1.0--
Apporaclefinancial_services_funds_transfer_pricing8.0.6--
Apporaclefinancial_services_funds_transfer_pricing8.0.7--
Apporaclefinancial_services_funds_transfer_pricing8.1.0--
Apporaclefinancial_services_hedge_management_and_ifrs_valuations---
Apporaclefinancial_services_hedge_management_and_ifrs_valuations8.1.0--
Apporaclefinancial_services_institutional_performance_analytics8.0.6--
Apporaclefinancial_services_institutional_performance_analytics8.0.7--
Apporaclefinancial_services_institutional_performance_analytics8.1.0--
Apporaclefinancial_services_liquidity_risk_management8.0.6--
Apporaclefinancial_services_liquidity_risk_measurement_and_management8.0.7--
Apporaclefinancial_services_liquidity_risk_measurement_and_management8.0.8--
Apporaclefinancial_services_liquidity_risk_measurement_and_management8.1.0--
Apporaclefinancial_services_loan_loss_forecasting_and_provisioning---
Apporaclefinancial_services_loan_loss_forecasting_and_provisioning8.1.0--
Apporaclefinancial_services_market_risk_measurement_and_management8.0.6--
Apporaclefinancial_services_market_risk_measurement_and_management8.0.8--
Apporaclefinancial_services_price_creation_and_discovery8.0.6--
Apporaclefinancial_services_price_creation_and_discovery8.0.7--
Apporaclefinancial_services_profitability_management8.0.6--
Apporaclefinancial_services_profitability_management8.0.7--
Apporaclefinancial_services_profitability_management8.1.0--
Apporaclefinancial_services_regulatory_reporting_for_european_banking_authority---
Apporaclefinancial_services_regulatory_reporting_for_us_federal_reserve---
Apporaclehealthcare_foundation7.1.1--
Apporaclehealthcare_foundation7.2.0--
Apporaclehealthcare_foundation7.2.1--
Apporaclehealthcare_foundation7.3.0--
Apporaclehospitality_materials_control18.1--
Apporaclehospitality_simphony---
Apporaclehospitality_simphony18.1--
Apporaclehospitality_simphony18.2--
Apporaclehospitality_simphony19.1.0-19.1.2--
Apporacleinsurance_accounting_analyzer8.0.9--
Apporacleinsurance_allocation_manager_for_enterprise_profitability8.0.8--
Apporacleinsurance_allocation_manager_for_enterprise_profitability8.1.0--
Apporacleinsurance_data_foundation---
Apporacleinsurance_data_foundation8.0.6-8.1.0--
Apporacleinsurance_insbridge_rating_and_underwriting---
Apporacleinsurance_insbridge_rating_and_underwriting5.6.1.0--
Apporaclejdeveloper11.1.1.9.0--
Apporaclejdeveloper12.2.1.3.0--
Apporaclejdeveloper12.2.1.4.0--
Apporaclepeoplesoft_enterprise_peopletools8.56--
Apporaclepeoplesoft_enterprise_peopletools8.57--
Apporaclepeoplesoft_enterprise_peopletools8.58--
Apporaclepolicy_automation---
Apporaclepolicy_automation_connector_for_siebel10.4.6--
Apporaclepolicy_automation_for_mobile_devices---
Apporacleretail_back_office14.0--
Apporacleretail_back_office14.1--
Apporacleretail_customer_management_and_segmentation_foundation19.0--
Apporacleretail_returns_management14.0--
Apporacleretail_returns_management14.1--
Apporaclesiebel_ui_framework20.8--
Apporaclestoragetek_acsls8.5.1--
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--
Apptenablelog_correlation_engine---

Explore more