Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12.3X48-D86, 12.3X48-D90 on SRX Series; 14.1X53 versions prior to 14.1X53-D51 on EX and QFX Series; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D592 on EX2300/EX3400 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S6, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R2-S5, 18.2R3; 18.3 versions prior to 18.3R1-S6, 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2; 19.1 versions prior to 19.1R1-S2, 19.1R2.
References
Link | Resource |
---|---|
https://kb.juniper.net/JSA10986 | Vendor Advisory |
https://kb.juniper.net/JSA10986 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
21 Nov 2024, 05:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://kb.juniper.net/JSA10986 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 7.5 |
Information
Published : 2020-01-15 09:15
Updated : 2024-11-21 05:10
NVD link : CVE-2020-1607
Mitre link : CVE-2020-1607
CVE.ORG link : CVE-2020-1607
JSON object : View
Products Affected
juniper
- srx1400
- srx300
- srx4600
- qfx10016
- srx3600
- qfx10008
- srx210
- junos
- qfx10002
- ex4300
- srx340
- qfx5100
- srx550
- qfx3000-g
- srx4200
- srx3400
- ex2300
- qfx3600-i
- qfx3008-i
- srx5800
- qfx5110
- srx345
- ex2300-c
- srx1500
- srx220
- ex9250
- srx650
- qfx3100
- qfx5200
- qfx3000-m
- srx5600
- srx5400
- ex3400
- ex9200
- srx100
- qfx3500
- qfx5210
- srx110
- srx320
- srx240
- ex4650
- ex4600
- srx4100
- qfx3600
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')