Multiple vulnerabilities exist in J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service. The cross site scripting vulnerability may allow a remote network based attacker to steal sensitive information such as session credentials from an administrative user or perform administrative actions through an administrative user's browser. This issue was discovered by an external security researcher. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. This issue has been assigned CVE-2014-6447 .
The following software releases have been updated to resolve these specific issues: Junos OS 12.1X44-D45, 12.1X46-D30, 12.1X47-D20, 12.3R8, 12.3X48-D10, 13.1R5, 13.2R6, 13.3R4, 14.1R3, 14.1X53-D10, 14.2R1, 15.1R1, and all subsequent releases. This issue is being tracked as PR 959990 and is visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Disable J-Web or to reduce the risks of exploitation due to this vulnerability limit J-Web access to only trusted hosts.
2015-07-08: Initial publication 2015-07-14: Added 14.1X53-D10 to list of fixed releases.
The Juniper SIRT would like to acknowledge and thank Kyle Lovett for responsibly reporting this vulnerability.