CVE-2022-22242
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9.
19.2 versions prior to 19.2R3-S6.
19.3 versions prior to 19.3R3-S7.
19.4 versions prior to 19.4R2-S7, 19.4R3-S8.
20.1 versions prior to 20.1R3-S5.
20.2 versions prior to 20.2R3-S5.
20.3 versions prior to 20.3R3-S5.
20.4 versions prior to 20.4R3-S4.
21.1 versions prior to 21.1R3-S4.
21.2 versions prior to 21.2R3-S1.
21.3 versions prior to 21.3R3.
21.4 versions prior to 21.4R2.
22.1 versions prior to 22.1R2.
MEDIUM · CVSS 6.1
EPSS 0.64552
Act now
- EPSS ≥ 0.50 - high probability of exploitation in the next 30 days
- EPSS percentile: top 2% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0