QID 43831

Date Published: 2021-06-03

QID 43831: Juniper Junos J-Web Path traversal vulnerability (JSA11126)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

Junos OS: SRX Series: J-Web Path traversal vulnerability in SRX Series leads to information disclosure. Affected releases are Junos OS:
19.3 versions prior to 19.3R2-S6, 19.3R3-S1;
19.4 versions prior to 19.4R2-S4, 19.4R3;
20.1 versions prior to 20.1R1-S4, 20.1R2;
20.2 versions prior to 20.2R1-S3, 20.2R2;
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.

Successful exploitation allows attackers to execute remote code.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The vendor has released fixes.
    The following software releases have been updated to resolve these specific issues:
    The following software releases have been updated to resolve this specific issue: 19.3R2-S6, 19.3R3-S1, 19.4R2-S4, 19.4R3, 20.1R1-S4, 20.1R2, 20.2R1-S3, 20.2R2, 20.3R1, and all subsequent releases.

    For more information please visit JSA11126.

    CVEs related to QID 43831

    Software Advisories
    Advisory ID Software Component Link
    JSA11126 URL Logo kb.juniper.net/InfoCenter/index?page=content&id=JSA11126&actp=METADATA