Multiple vulnerabilities exist in J-Web input handling that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS). The cross-site request forgery vulnerabilities may allow malicious content on third party websites to launch unauthorized access and actions against J-Web via an administrative user's browser. These issues were found during internal product security testing. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. This set of issues has been assigned CVE-2016-1261 .
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X44-D55, 12.1X46-D45, 12.1X47-D30, 12.3R11, 12.3X48-D30, 13.2X51-D40, 13.3R8, 14.1R6, 14.1X53-D30, 14.2R5, 15.1R3, 15.1X49-D20, and all subsequent releases. These issues are being tracked as PRs 1085861, 1085470, 1085428, 1084495, and 1082543, and are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Disable J-Web, or limit access to only trusted hosts which may not be compromised by cross-site attacks. For example, deploy jump hosts with no Internet access that use anti-scripting techniques to mitigate potential threats. Alternately, use a dedicated client and dedicated Web browser that is not used to access other sites.
2016-04-13: Initial publication