4.3

CVE-2015-3004

J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D10, 12.3X48 before 12.3X48-D10, 12.2 before 12.2R9, 12.3 before 12.3R7, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R5, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, and 14.2 before 14.2R1 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 12.1x44
Juniper ≫ Junos Version 12.1x44 Update d10
Juniper ≫ Junos Version 12.1x44 Update d15
Juniper ≫ Junos Version 12.1x44 Update d20
Juniper ≫ Junos Version 12.1x44 Update d25
Juniper ≫ Junos Version 12.1x44 Update d30
Juniper ≫ Junos Version 12.1x46
Juniper ≫ Junos Version 12.1x46 Update d10
Juniper ≫ Junos Version 12.1x46 Update d15
Juniper ≫ Junos Version 12.1x46 Update d20
Juniper ≫ Junos Version 12.1x47
Juniper ≫ Junos Version 12.2
Juniper ≫ Junos Version 12.2 Update r1
Juniper ≫ Junos Version 12.2 Update r2
Juniper ≫ Junos Version 12.2 Update r3
Juniper ≫ Junos Version 12.2 Update r4
Juniper ≫ Junos Version 12.2 Update r5
Juniper ≫ Junos Version 12.2 Update r6
Juniper ≫ Junos Version 12.2 Update r7
Juniper ≫ Junos Version 12.2 Update r8
Juniper ≫ Junos Version 12.2 Update r8-s2
Juniper ≫ Junos Version 12.3 Update r1
Juniper ≫ Junos Version 12.3 Update r2
Juniper ≫ Junos Version 12.3 Update r3
Juniper ≫ Junos Version 12.3 Update r4
Juniper ≫ Junos Version 12.3 Update r5
Juniper ≫ Junos Version 12.3 Update r6
Juniper ≫ Junos Version 12.3x48
Juniper ≫ Junos Version 13.2
Juniper ≫ Junos Version 13.2 Update r1
Juniper ≫ Junos Version 13.2 Update r2
Juniper ≫ Junos Version 13.2 Update r3
Juniper ≫ Junos Version 13.2 Update r4
Juniper ≫ Junos Version 13.2 Update r5
Juniper ≫ Junos Version 13.2x51
Juniper ≫ Junos Version 13.2x51 Update d10
Juniper ≫ Junos Version 13.2x51 Update d15
Juniper ≫ Junos Version 13.3
Juniper ≫ Junos Version 13.3 Update r1
Juniper ≫ Junos Version 13.3 Update r2
Juniper ≫ Junos Version 13.3 Update r2-s2
Juniper ≫ Junos Version 13.3 Update r3
Juniper ≫ Junos Version 13.3 Update r4
Juniper ≫ Junos Version 14.1
Juniper ≫ Junos Version 14.1 Update r1
Juniper ≫ Junos Version 14.1 Update r2
Juniper ≫ Junos Version 14.1x53
Juniper ≫ Junos Version 14.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.762
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/74017
http://www.securitytracker.com/id/1032090
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10675
Vendor Advisory