CVE-2013-6956: XSS
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Junos Pulse Secure Access Service (SSL VPN) / Secure Access Service Web rewriting feature (IVE OS)to a version that resolves this vulnerability.Fixed in 7.1r17 - Upgrade
Upgrade
Juniper Junos Pulse Secure Access Service (SSL VPN) / Secure Access Service Web rewriting feature (IVE OS)to a version that resolves this vulnerability.Fixed in 7.3r8 - Upgrade
Upgrade
Juniper Junos Pulse Secure Access Service (SSL VPN) / Secure Access Service Web rewriting feature (IVE OS)to a version that resolves this vulnerability.Fixed in 7.4r6 - Upgrade
Upgrade
Juniper Junos Pulse Secure Access Service (SSL VPN) / Secure Access Service Web rewriting feature (IVE OS)to a version that resolves this vulnerability.Fixed in 8.0r1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6956?
CVE-2013-6956 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-6956?
To mitigate CVE-2013-6956, upgrade to Junos Pulse Secure Access Service versions 7.1r17, 7.3r8, 7.4r6, or 8.0r1 or later.
Who is affected by CVE-2013-6956?
CVE-2013-6956 affects users utilizing Juniper Junos Pulse Secure Access Service with web rewriting feature enabled on specified versions of IVE OS.
What type of attack can be executed via CVE-2013-6956?
CVE-2013-6956 allows remote authenticated attackers to execute cross-site scripting (XSS) attacks.
When was CVE-2013-6956 disclosed?
CVE-2013-6956 was publicly disclosed in 2013.