First published: Wed Jan 15 2020(Updated: )
Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12.3X48-D86, 12.3X48-D90 on SRX Series; 14.1X53 versions prior to 14.1X53-D51 on EX and QFX Series; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D592 on EX2300/EX3400 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S6, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R2-S5, 18.2R3; 18.3 versions prior to 18.3R1-S6, 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2; 19.1 versions prior to 19.1R1-S2, 19.1R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =12.3 | |
Juniper JUNOS | =12.3-r1 | |
Juniper JUNOS | =12.3-r11 | |
Juniper JUNOS | =12.3-r12 | |
Juniper JUNOS | =12.3-r12-s1 | |
Juniper JUNOS | =12.3-r12-s10 | |
Juniper JUNOS | =12.3-r12-s11 | |
Juniper JUNOS | =12.3-r12-s12 | |
Juniper JUNOS | =12.3-r12-s13 | |
Juniper JUNOS | =12.3-r12-s14 | |
Juniper JUNOS | =12.3-r12-s3 | |
Juniper JUNOS | =12.3-r12-s4 | |
Juniper JUNOS | =12.3-r12-s6 | |
Juniper JUNOS | =12.3-r13 | |
Juniper JUNOS | =12.3-r2 | |
Juniper JUNOS | =12.3-r3 | |
Juniper JUNOS | =12.3-r4 | |
Juniper JUNOS | =12.3-r5 | |
Juniper JUNOS | =12.3-r6 | |
Juniper JUNOS | =12.3-r7 | |
Juniper JUNOS | =12.3-r8 | |
Juniper JUNOS | =12.3-r9 | |
Juniper JUNOS | =15.1-f6 | |
Juniper JUNOS | =15.1-f6-s1 | |
Juniper JUNOS | =15.1-f6-s12 | |
Juniper JUNOS | =15.1-f6-s3 | |
Juniper JUNOS | =15.1-r1 | |
Juniper JUNOS | =15.1-r2 | |
Juniper JUNOS | =15.1-r3 | |
Juniper JUNOS | =15.1-r4 | |
Juniper JUNOS | =15.1-r4-s9 | |
Juniper JUNOS | =15.1-r5 | |
Juniper JUNOS | =15.1-r6 | |
Juniper JUNOS | =15.1-r6-s6 | |
Juniper JUNOS | =15.1-r7-s1 | |
Juniper JUNOS | =15.1-r7-s2 | |
Juniper JUNOS | =15.1-r7-s3 | |
Juniper JUNOS | =15.1-r7-s4 | |
Juniper JUNOS | =16.1 | |
Juniper JUNOS | =16.1-r1 | |
Juniper JUNOS | =16.1-r2 | |
Juniper JUNOS | =16.1-r3 | |
Juniper JUNOS | =16.1-r3-s10 | |
Juniper JUNOS | =16.1-r4 | |
Juniper JUNOS | =16.1-r4-s12 | |
Juniper JUNOS | =16.1-r4-s2 | |
Juniper JUNOS | =16.1-r4-s3 | |
Juniper JUNOS | =16.1-r4-s6 | |
Juniper JUNOS | =16.1-r4-s9 | |
Juniper JUNOS | =16.1-r5-s4 | |
Juniper JUNOS | =16.1-r6-s1 | |
Juniper JUNOS | =16.1-r7 | |
Juniper JUNOS | =16.1-r7-s2 | |
Juniper JUNOS | =16.1-r7-s3 | |
Juniper JUNOS | =16.1-r7-s4 | |
Juniper JUNOS | =16.2 | |
Juniper JUNOS | =16.2-r1 | |
Juniper JUNOS | =16.2-r2 | |
Juniper JUNOS | =16.2-r2-s1 | |
Juniper JUNOS | =16.2-r2-s2 | |
Juniper JUNOS | =16.2-r2-s5 | |
Juniper JUNOS | =16.2-r2-s6 | |
Juniper JUNOS | =16.2-r2-s7 | |
Juniper JUNOS | =16.2-r2-s8 | |
Juniper JUNOS | =16.2-r2-s9 | |
Juniper JUNOS | =17.1 | |
Juniper JUNOS | =17.1-r1 | |
Juniper JUNOS | =17.1-r2-s1 | |
Juniper JUNOS | =17.1-r2-s10 | |
Juniper JUNOS | =17.1-r2-s2 | |
Juniper JUNOS | =17.1-r2-s3 | |
Juniper JUNOS | =17.1-r2-s4 | |
Juniper JUNOS | =17.1-r2-s5 | |
Juniper JUNOS | =17.1-r2-s6 | |
Juniper JUNOS | =17.1-r2-s7 | |
Juniper JUNOS | =17.1-r3 | |
Juniper JUNOS | =17.2 | |
Juniper JUNOS | =17.2-r1-s2 | |
Juniper JUNOS | =17.2-r1-s4 | |
Juniper JUNOS | =17.2-r1-s7 | |
Juniper JUNOS | =17.2-r1-s8 | |
Juniper JUNOS | =17.2-r2-s6 | |
Juniper JUNOS | =17.2-r2-s7 | |
Juniper JUNOS | =17.3 | |
Juniper JUNOS | =17.3-r1-s1 | |
Juniper JUNOS | =17.3-r2 | |
Juniper JUNOS | =17.3-r2-s1 | |
Juniper JUNOS | =17.3-r2-s2 | |
Juniper JUNOS | =17.3-r2-s4 | |
Juniper JUNOS | =17.3-r3-s1 | |
Juniper JUNOS | =17.3-r3-s2 | |
Juniper JUNOS | =17.3-r3-s3 | |
Juniper JUNOS | =17.3-r3-s4 | |
Juniper JUNOS | =17.4 | |
Juniper JUNOS | =17.4-r1 | |
Juniper JUNOS | =17.4-r1-s1 | |
Juniper JUNOS | =17.4-r1-s2 | |
Juniper JUNOS | =17.4-r1-s4 | |
Juniper JUNOS | =17.4-r1-s6 | |
Juniper JUNOS | =17.4-r1-s7 | |
Juniper JUNOS | =17.4-r2 | |
Juniper JUNOS | =17.4-r2-s1 | |
Juniper JUNOS | =17.4-r2-s3 | |
Juniper JUNOS | =17.4-r2-s4 | |
Juniper JUNOS | =17.4-r2-s5 | |
Juniper JUNOS | =18.1 | |
Juniper JUNOS | =18.1-r2 | |
Juniper JUNOS | =18.1-r2-s1 | |
Juniper JUNOS | =18.1-r2-s2 | |
Juniper JUNOS | =18.1-r2-s4 | |
Juniper JUNOS | =18.1-r3 | |
Juniper JUNOS | =18.1-r3-s1 | |
Juniper JUNOS | =18.1-r3-s2 | |
Juniper JUNOS | =18.1-r3-s3 | |
Juniper JUNOS | =18.1-r3-s4 | |
Juniper JUNOS | =18.1-r3-s5 | |
Juniper JUNOS | =18.1-r3-s6 | |
Juniper JUNOS | =18.2 | |
Juniper JUNOS | =18.2-r1-s5 | |
Juniper JUNOS | =18.2-r2-s1 | |
Juniper JUNOS | =18.2-r2-s2 | |
Juniper JUNOS | =18.2-r2-s3 | |
Juniper JUNOS | =18.2-r2-s4 | |
Juniper JUNOS | =18.3 | |
Juniper JUNOS | =18.3-r1 | |
Juniper JUNOS | =18.3-r1-s1 | |
Juniper JUNOS | =18.3-r1-s2 | |
Juniper JUNOS | =18.3-r1-s3 | |
Juniper JUNOS | =18.3-r1-s4 | |
Juniper JUNOS | =18.3-r1-s5 | |
Juniper JUNOS | =18.3-r2 | |
Juniper JUNOS | =18.4 | |
Juniper JUNOS | =18.4-r1 | |
Juniper JUNOS | =18.4-r1-s1 | |
Juniper JUNOS | =18.4-r1-s2 | |
Juniper JUNOS | =18.4-r1-s3 | |
Juniper JUNOS | =18.4-r1-s4 | |
Juniper JUNOS | =19.1-r1 | |
Juniper JUNOS | =19.1-r1-s1 | |
Juniper JUNOS | =12.3x48-d10 | |
Juniper JUNOS | =12.3x48-d15 | |
Juniper JUNOS | =12.3x48-d25 | |
Juniper JUNOS | =12.3x48-d80 | |
Juniper JUNOS | =15.1x49-d10 | |
Juniper JUNOS | =15.1x49-d150 | |
Juniper JUNOS | =15.1x49-d170 | |
Juniper JUNOS | =15.1x49-d180 | |
Juniper JUNOS | =15.1x49-d20 | |
Juniper JUNOS | =15.1x49-d30 | |
Juniper JUNOS | =15.1x49-d35 | |
Juniper JUNOS | =15.1x49-d40 | |
Juniper JUNOS | =15.1x49-d45 | |
Juniper JUNOS | =15.1x49-d50 | |
Juniper JUNOS | =15.1x49-d55 | |
Juniper JUNOS | =15.1x49-d60 | |
Juniper JUNOS | =15.1x49-d65 | |
Juniper JUNOS | =15.1x49-d70 | |
Juniper JUNOS | =15.1x49-d75 | |
Juniper JUNOS | =15.1x49-d80 | |
Juniper JUNOS | =15.1x49-d90 | |
Juniper Srx100 | ||
Juniper Srx110 | ||
Juniper Srx1400 | ||
Juniper Srx1500 | ||
Juniper Srx210 | ||
Juniper Srx220 | ||
Juniper Srx240 | ||
Juniper Srx300 | ||
Juniper Srx320 | ||
Juniper Srx340 | ||
Juniper Srx3400 | ||
Juniper Srx345 | ||
Juniper Srx3600 | ||
Juniper Srx4100 | ||
Juniper Srx4200 | ||
Juniper Srx4600 | ||
Juniper Srx5400 | ||
Juniper Srx550 | ||
Juniper Srx5600 | ||
Juniper Srx5800 | ||
Juniper Srx650 | ||
Juniper JUNOS | =14.1x53 | |
Juniper JUNOS | =14.1x53-d10 | |
Juniper JUNOS | =14.1x53-d15 | |
Juniper JUNOS | =14.1x53-d16 | |
Juniper JUNOS | =14.1x53-d25 | |
Juniper JUNOS | =14.1x53-d26 | |
Juniper JUNOS | =14.1x53-d27 | |
Juniper JUNOS | =14.1x53-d30 | |
Juniper JUNOS | =14.1x53-d35 | |
Juniper JUNOS | =14.1x53-d40 | |
Juniper JUNOS | =14.1x53-d45 | |
Juniper JUNOS | =14.1x53-d46 | |
Juniper JUNOS | =14.1x53-d47 | |
Juniper JUNOS | =14.1x53-d48 | |
Juniper JUNOS | =14.1x53-d49 | |
Juniper Ex2300 | ||
Juniper Ex2300-c | ||
Juniper Ex3400 | ||
Juniper Ex4300 | ||
Juniper EX4600 | ||
Juniper Ex4650 | ||
Juniper Ex9200 | ||
Juniper Ex9250 | ||
Juniper Qfx10002 | ||
Juniper Qfx10008 | ||
Juniper Qfx10016 | ||
Juniper Qfx3000-g | ||
Juniper Qfx3000-m | ||
Juniper Qfx3008-i | ||
Juniper Qfx3100 | ||
Juniper Qfx3500 | ||
Juniper Qfx3600 | ||
Juniper Qfx3600-i | ||
Juniper Qfx5100 | ||
Juniper Qfx5110 | ||
Juniper Qfx5200 | ||
Juniper Qfx5210 | ||
Juniper JUNOS | =15.1x53-d20 | |
Juniper JUNOS | =15.1x53-d21 | |
Juniper JUNOS | =15.1x53-d210 | |
Juniper JUNOS | =15.1x53-d230 | |
Juniper JUNOS | =15.1x53-d231 | |
Juniper JUNOS | =15.1x53-d232 | |
Juniper JUNOS | =15.1x53-d233 | |
Juniper JUNOS | =15.1x53-d234 | |
Juniper JUNOS | =15.1x53-d235 | |
Juniper JUNOS | =15.1x53-d236 | |
Juniper JUNOS | =15.1x53-d237 | |
Juniper JUNOS | =15.1x53-d25 | |
Juniper JUNOS | =15.1x53-d30 | |
Juniper JUNOS | =15.1x53-d31 | |
Juniper JUNOS | =15.1x53-d32 | |
Juniper JUNOS | =15.1x53-d33 | |
Juniper JUNOS | =15.1x53-d34 | |
Juniper JUNOS | =15.1x53-d40 | |
Juniper JUNOS | =15.1x53-d45 | |
Juniper JUNOS | =15.1x53-d56 | |
Juniper JUNOS | =15.1x53-d60 | |
Juniper JUNOS | =15.1x53-d61 | |
Juniper JUNOS | =15.1x53-d62 | |
Juniper JUNOS | =15.1x53-d63 | |
Juniper JUNOS | =15.1x53-d65 | |
Juniper JUNOS | =15.1x53-d70 | |
Juniper JUNOS | =15.1x53-d470 | |
Juniper JUNOS | =15.1x53-d495 | |
Juniper JUNOS | =15.1x53-d590 | |
Juniper JUNOS | =15.1x53-d591 |
The following software releases have been updated to resolve this specific issue: 12.3R12-S15, 12.3X48-D86, 12.3X48-D90, 14.1X53-D51, 15.1F6-S13,15.1R7-S5, 15.1X49-D181, 15.1X49-D190, 15.1X53-D238, 15.1X53-D592, 16.1R4-S13, 16.1R7-S5, 16.2R2-S10,17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R3-S2, 17.3R2-S5, 17.3R3-S5, 17.4R2-S6, 17.4R3, 18.1R3-S7,18.2R2-S5, 18.2R3, 18.3R1-S6, 18.3R2-S1, 18.3R3, 18.4R1-S5, 18.4R2, 19.1R1-S2, 19.1R2, 19.2R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.