Persistent XSS Vulnerability in Juniper ATP 5.0 Allows for Arbitrary Script Injection and Data Theft

Persistent XSS Vulnerability in Juniper ATP 5.0 Allows for Arbitrary Script Injection and Data Theft

CVE-2019-0027 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

Learn more about our Cis Benchmark Audit For Juniper.