{"api_version":"1","generated_at":"2026-07-23T11:57:27+00:00","cve":"CVE-2012-1038","urls":{"html":"https://cve.report/CVE-2012-1038","api":"https://cve.report/api/cve/CVE-2012-1038.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-1038","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-1038"},"summary":{"title":"CVE-2012-1038","description":"Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.","state":"PUBLISHED","assigner":"mitre","published_at":"2013-04-03 00:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view","name":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Juniper Networks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf","name":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 | Secureworks","mime":"application/pdf","httpstatus":"404","archivestatus":"200"},{"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/","name":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Juniper Mobility System Software (MSS) web portal WebAAA cross-site scripting (XSS) | Dell SecureWorks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-1038","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1038","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.5.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"1038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"networks_mobility_system_software","cpe6":"7.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:45:27.131Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-06-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-09-27T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf"},{"tags":["x_refsource_MISC"],"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-1038","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf","refsource":"MISC","url":"http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdf"},{"name":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/","refsource":"MISC","url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/"},{"name":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view","refsource":"CONFIRM","url":"http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=view"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-1038","datePublished":"2013-04-03T00:00:00.000Z","dateReserved":"2012-02-08T00:00:00.000Z","dateUpdated":"2024-08-06T18:45:27.131Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-04-03 00:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.3:*:*:*:*:*:*:*","matchCriteriaId":"EE0B0C6B-19F4-4858-8E6A-2A15F6D4537B"},{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.4:*:*:*:*:*:*:*","matchCriteriaId":"21339039-0AF7-49AF-9A73-D5B0E667C190"},{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.5:*:*:*:*:*:*:*","matchCriteriaId":"CEAB8428-CA92-4DAD-9588-C5D583CA0245"},{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.5.1.6:*:*:*:*:*:*:*","matchCriteriaId":"01B87B13-5C8B-4E4D-9B5A-670E3A7D9CAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.6:*:*:*:*:*:*:*","matchCriteriaId":"65790546-2DE0-4D55-BAD6-52B3BCA3758C"},{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:networks_mobility_system_software:7.7:*:*:*:*:*:*:*","matchCriteriaId":"C0FFAF0D-83BE-431D-956D-FAD9E5FE7F57"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"1038","Ordinal":"1","Title":"CVE-2012-1038","CVE":"CVE-2012-1038","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"1038","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.","Type":"Description","Title":"CVE-2012-1038"},{"CveYear":"2012","CveId":"1038","Ordinal":"2","NoteData":"2013-04-02","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"1038","Ordinal":"3","NoteData":"2016-09-27","Type":"Other","Title":"Modified"}]}}}