A cross-site scripting (XSS) vulnerability in the IDP ACM (Appliance Configuration Manager) may allow arbitrary instructions to be executed by a user in the user's browser and without the user's knowledge. No other Juniper Networks products are affected by this vulnerability. This issue was reported by JPCERT on behalf of an anonymous referrer, but Juniper had discovered and repaired the issue internally prior to the external notice.
IDP 4.1r3, IDP 4.2r1 and later versions have been modified to eliminate this vulnerability. We strongly urge all customers who are currently on versions earlier than 4.1r3 to upgrade. If a software upgrade is not feasible, customers should limit access to the IDP ACM user interface, or disable management via the IDP ACM web interface if it is not needed.
2017-03-05: Category restructure.