7.1

CVE-2014-6447

Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, 14.2 before 14.2R1, and 15.1 before 15.1R1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 12.1x44 Update -
Juniper ≫ Junos Version 12.1x44 Update d10
Juniper ≫ Junos Version 12.1x44 Update d15
Juniper ≫ Junos Version 12.1x44 Update d20
Juniper ≫ Junos Version 12.1x44 Update d25
Juniper ≫ Junos Version 12.1x44 Update d30
Juniper ≫ Junos Version 12.1x44 Update d35
Juniper ≫ Junos Version 12.1x44 Update d40
Juniper ≫ Junos Version 12.1x46 Update -
Juniper ≫ Junos Version 12.1x46 Update d10
Juniper ≫ Junos Version 12.1x46 Update d15
Juniper ≫ Junos Version 12.1x46 Update d20
Juniper ≫ Junos Version 12.1x46 Update d25
Juniper ≫ Junos Version 12.1x47 Update -
Juniper ≫ Junos Version 12.1x47 Update d10
Juniper ≫ Junos Version 12.1x47 Update d15
Juniper ≫ Junos Version 12.3 Update -
Juniper ≫ Junos Version 12.3 Update r1
Juniper ≫ Junos Version 12.3 Update r2
Juniper ≫ Junos Version 12.3 Update r3
Juniper ≫ Junos Version 12.3 Update r4
Juniper ≫ Junos Version 12.3 Update r5
Juniper ≫ Junos Version 12.3 Update r6
Juniper ≫ Junos Version 12.3 Update r7
Juniper ≫ Junos Version 12.3x48 Update -
Juniper ≫ Junos Version 13.1 Update -
Juniper ≫ Junos Version 13.1 Update r1
Juniper ≫ Junos Version 13.1 Update r2
Juniper ≫ Junos Version 13.1 Update r3
Juniper ≫ Junos Version 13.1 Update r4
Juniper ≫ Junos Version 13.1 Update r4-s2
Juniper ≫ Junos Version 13.2 Update -
Juniper ≫ Junos Version 13.2 Update r1
Juniper ≫ Junos Version 13.2 Update r2
Juniper ≫ Junos Version 13.2 Update r3
Juniper ≫ Junos Version 13.2 Update r4
Juniper ≫ Junos Version 13.2 Update r5
Juniper ≫ Junos Version 13.3 Update -
Juniper ≫ Junos Version 13.3 Update r1
Juniper ≫ Junos Version 13.3 Update r10
Juniper ≫ Junos Version 13.3 Update r2
Juniper ≫ Junos Version 13.3 Update r2-s2
Juniper ≫ Junos Version 13.3 Update r3
Juniper ≫ Junos Version 14.1 Update -
Juniper ≫ Junos Version 14.1 Update r1
Juniper ≫ Junos Version 14.1 Update r2
Juniper ≫ Junos Version 14.1x53 Update -
Juniper ≫ Junos Version 14.2 Update -
Juniper ≫ Junos Version 15.1 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.581
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 2.8 3.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10682
Vendor Advisory
http://www.securitytracker.com/id/1032846
Third Party Advisory
VDB Entry