VulnerabilityModified
CVE-2012-5460
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText…
MEDIUM 4.3EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- juniper/ive os · juniper/secure access virtual appliance · juniper/fips secure access 4000 · juniper/fips secure access 4500 · juniper/fips secure access 6000 · juniper/fips secure access 6500 · juniper/mag2600 gateway · juniper/mag4610 gateway · juniper/mag6610 gateway · juniper/mag6611 gateway · juniper/secure access 2000 · juniper/secure access 2500 · juniper/secure access 4000 · juniper/secure access 4500 · juniper/secure access 6000 · juniper/secure access 6500 · juniper/secure access 700
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0148.html
- http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-03-874&viewMode=viewVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0148.html
- http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-03-874&viewMode=viewVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.