Vulnerability Description
Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, 14.2 before 14.2R1, and 15.1 before 15.1R1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 12.1x44 |
Related Weaknesses (CWE)
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10682Vendor Advisory
- http://www.securitytracker.com/id/1032846Third Party AdvisoryVDB Entry
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10682Vendor Advisory
- http://www.securitytracker.com/id/1032846Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-6447?
CVE-2014-6447 is a vulnerability with a CVSS score of 7.1 (HIGH). Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 1...
How severe is CVE-2014-6447?
CVE-2014-6447 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-6447?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos.