5.4
CVE-2018-0047
- EPSS 0.86%
- Veröffentlicht 10.10.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:37:25
- Erkennungen
Junos Space Security Director: XSS vulnerability in web administration
A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Space Version 13.3 Update r1
Juniper ≫ Junos Space Version 13.3 Update r2
Juniper ≫ Junos Space Version 14.1 Update r1
Juniper ≫ Junos Space Version 14.1 Update r2
Juniper ≫ Junos Space Version 14.1 Update r3
Juniper ≫ Junos Space Version 15.1 Update r1
Juniper ≫ Junos Space Version 15.1 Update r2
Juniper ≫ Junos Space Version 15.1 Update r3
Juniper ≫ Junos Space Version 15.1 Update r4
Juniper ≫ Junos Space Version 15.2 Update r1
Juniper ≫ Junos Space Version 15.2 Update r2
Juniper ≫ Junos Space Version 16.1 Update r1
Juniper ≫ Junos Space Version 16.1 Update r2
Juniper ≫ Junos Space Version 16.1 Update r3
Juniper ≫ Junos Space Version 17.1 Update r1
Juniper ≫ Junos Space Version 17.2 Update r1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.538 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
| Juniper | 8 | 2.1 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://www.securitytracker.com/id/1041863
https://kb.juniper.net/JSA10881