CVE-2018-0047 PUBLISHED CVSS 8 HIGH

A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2.

EPSS 0.32% · 54.6th percentile

Risk Scores

CVSS v3.0
8
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.32%
54.6th percentile

Affected Products

VendorProductVersions
Juniper NetworksJunos Space Security Directorunspecified
juniperjunos_space13.3, 13.3, 14.1

Timeline

References

Open in Interactive Console →