Vulnerability Name:

CVE-2009-3486 (CCN-53501)

Assigned:2009-09-22
Published:2009-09-22
Updated:2009-10-05
Summary:Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
3.3 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-3486

Source: CCN
Type: SA36829
Juniper JUNOS JWeb Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
36829

Source: CCN
Type: Juniper Networks Web site
Juniper Networks JUNOS

Source: CCN
Type: OSVDB ID: 58512
Juniper Junos J-Web Interface /diagnose Multiple Parameter XSS

Source: CCN
Type: OSVDB ID: 58513
Juniper Junos J-Web Interface /configuration Multiple Parameter XSS

Source: CCN
Type: PR09-08
Juniper JunOS JWeb (Juniper Web Management) XSS

Source: MISC
Type: Exploit
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-09

Source: BID
Type: Exploit
36537

Source: CCN
Type: BID-36537
Juniper Networks JUNOS J-Web Multiple Cross Site Scripting And HTML Injection Vulnerabilities

Source: VUPEN
Type: Vendor Advisory
ADV-2009-2784

Source: XF
Type: UNKNOWN
junos-jweb-xss(53501)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:juniper:junos:8.5:r1.14:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:juniper:junos:9.0:r1.1:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.5:r1.14:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    juniper junos 8.5 r1.14
    juniper junos 9.0 r1.1
    juniper junos 8.5 r1.14