CVE-2012-5460: XSS
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5460?
CVE-2012-5460 is classified as a medium severity vulnerability due to its XSS nature, which can lead to the execution of malicious scripts.
How do I fix CVE-2012-5460?
To fix CVE-2012-5460, upgrade to Juniper Secure Access IVE OS version 7.1r13, 7.2r7, or 7.3r2 or higher.
What type of vulnerability is CVE-2012-5460?
CVE-2012-5460 is a cross-site scripting (XSS) vulnerability affecting Juniper Secure Access implementations.
Which Juniper products are affected by CVE-2012-5460?
CVE-2012-5460 affects Juniper Secure Access products running IVE OS versions prior to 7.1r13, 7.2r7, and 7.3r2.
What could exploitation of CVE-2012-5460 lead to?
Exploitation of CVE-2012-5460 could allow remote attackers to inject arbitrary web scripts or HTML into the affected application.