Vulnerability Description
A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Advanced Threat Prevention | >= 5.0.0, < 5.0.3 |
| Juniper | Atp400 | - |
| Juniper | Atp700 | - |
Related Weaknesses (CWE)
References
- https://kb.juniper.net/JSA10918PatchVendor Advisory
- https://kb.juniper.net/JSA10918PatchVendor Advisory
FAQ
What is CVE-2019-0026?
CVE-2019-0026 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a w...
How severe is CVE-2019-0026?
CVE-2019-0026 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0026?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Advanced Threat Prevention, Juniper Atp400, Juniper Atp700.