Vulnerable jquery JavaScript libraries
search cancel

Vulnerable jquery JavaScript libraries

book

Article ID: 273144

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager

Issue/Introduction

The vulnerability scan team identified that JQuery 1.9.0 libraries are vulnerable to various recognized attacks. Do we need to upgrade to the latest RU version available from Broadcom?

-SDM-server:port/CAisd/scripts/jquery/jquery-ui.min.js

-SDM-server:port/CAisd/scripts/jquery/jquery-1.9.0.min.js

Environment

Release: 17.3 +

Resolution

Yes, since the environment is currently patched with release RU07,  your implementation is missing numerous security patches provided with the later releases of RUs. The recommendation is to upgrade to RU19 at the minimum to mitigate the jQuery r1.9.0 vulnerability raised.

Security Enhancements provided with the latest releases.

1. Security vulnerabilities related to CA Asset Portfolio Management are addressed in CA Service Management 17.3.0.19.
2. The jquery-1.3.2 and jquery-ui-1.7.2 have been upgraded to jquery 3.6 and jquery-ui-1.13.2, respectively.

 

Additional Information

https://techdocs.broadcom.com/us/en/ca-enterprise-software/business-management/ca-service-management/17-3/Release-Information/CASM-17-3-0-19-Release-Notes.html#concept.dita_d3303fde-e786-4fd4-b0b6-e3a28fd60a82_SecurityEnhancements