Insufficient cross site scripting protection in J-Web may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data and credentials from a J-Web session and to perform administrative actions on the Junos device. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. This issue has been assigned CVE-2016-4923 .
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X44-D60, 12.1X46-D40, 12.1X47-D30, 12.3R11, 12.3X48-D20, 13.2X51-D39, 13.2X51-D40, 13.3R9, 14.1R6, 14.2R6, 15.1R3, 15.1X49-D20 and 16.1R1 and all subsequent releases. This issue is being tracked as PR 1085816 and is visible on the Customer Support website.
Access J-Web from trusted hosts which may not be compromised by cross-site scripting attacks, for example, deploying jump hosts with no internet access which use anti-scripting techniques to mitigate potential threats.
2016-10-12: Initial publication