IBM Support

webMethods Knowlegebase : Vulnerable Javascript Libraries, jQuery (1796283)

Troubleshooting


Problem

In a penetration security test it seems that the AAL application is found to be "USING COMPONENTS WITH KNOWN VULNERABILITIES (VULNERABLE JAVASCRIPT LIBRARIES)".

Evidence suggests that the impacted JS file uses jQuery v1.7.1 which is known to be vulnerable to CVE-2015-9251, CVE-2012-6708 and CVE-2019-11358

(Source: https://www.cvedetails.com/vulnerability-list/vendor_id-6538/product_id-11031/version_id-235564/Jquery-Jquery-1.7.1.html)

Document Location

Worldwide

[{"Line of Business":{"code":"","label":""},"Business Unit":{"code":"","label":""},"Product":{"code":"SSI42O","label":"IBM webMethods AgileApps SaaS"},"ARM Category":[{"code":"a8mKe00000000AQIAY","label":"webMethods AgileApps Cloud (LJP)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"SUSE Linux Enterprise Server"}],"Version":"10.9"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
20 March 2025

UID

ibm17204937