First published: Tue Oct 19 2021(Updated: )
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to delete files which may allow the attacker to disrupt the integrity and availability of the system.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Session and Resource Control | <4.12.0r5 | |
Juniper Session and Resource Control | >=4.13.0r1<4.13.0r3 |
The following software releases have been updated to resolve this specific issue: 4.12.0R5, 4.13.0R3, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31381 is a vulnerability in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series that allows a remote attacker to delete files and disrupt system integrity and availability.
CVE-2021-31381 has a severity rating of 9.1 (Critical).
Juniper Session and Resource Control versions between 4.12.0r5 and 4.13.0r3 are affected by CVE-2021-31381.
CVE-2021-31381 is associated with CWE-16 (Configuration).
Juniper Networks has released a security advisory (JSA11248) with remediation steps for CVE-2021-31381. Please refer to the advisory for detailed instructions.