CVE-2018-0047: Junos Space Security Director: XSS vulnerability in web administration
A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0047?
CVE-2018-0047 has a medium severity level due to its potential for persistent cross-site scripting in Junos Space Security Director.
How do I fix CVE-2018-0047?
To fix CVE-2018-0047, update your Junos Space Security Director to the latest patched version provided by Juniper Networks.
Which versions of Junos Space are affected by CVE-2018-0047?
CVE-2018-0047 affects numerous versions of Junos Space, including 13.3 through 17.2.
What type of vulnerability is CVE-2018-0047?
CVE-2018-0047 is categorized as a persistent cross-site scripting vulnerability.
Who can exploit CVE-2018-0047?
Authenticated users can exploit CVE-2018-0047 to inject malicious scripts into the Junos Space Security Director.