Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-5460


Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.


Published

2013-08-01T13:32:35.103

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper ive_os 7.1 Yes
Operating System juniper ive_os 7.2 Yes
Operating System juniper ive_os 7.3 Yes
Application juniper secure_access_virtual_appliance - Yes
Hardware juniper fips_secure_access_4000 - Yes
Hardware juniper fips_secure_access_4500 - Yes
Hardware juniper fips_secure_access_6000 - Yes
Hardware juniper fips_secure_access_6500 - Yes
Hardware juniper mag2600_gateway - Yes
Hardware juniper mag4610_gateway - Yes
Hardware juniper mag6610_gateway - Yes
Hardware juniper mag6611_gateway - Yes
Hardware juniper secure_access_2000 - Yes
Hardware juniper secure_access_2500 - Yes
Hardware juniper secure_access_4000 - Yes
Hardware juniper secure_access_4500 - Yes
Hardware juniper secure_access_6000 - Yes
Hardware juniper secure_access_6500 - Yes
Hardware juniper secure_access_700 - Yes

References