CVE-2015-3004

Description

J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D10, 12.3X48 before 12.3X48-D10, 12.2 before 12.2R9, 12.3 before 12.3R7, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R5, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, and 14.2 before 14.2R1 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.253

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-6378,CVE-2014-6386,CVE-2015-3004 are fixed in junos 12.1x44-d35NCM
Vulnerabilities CVE-2014-6378,CVE-2014-6384,CVE-2015-3004 are fixed in junos 12.1x46-d25NCM
Multiple Vulnerabilities are fixed in junos 12.1x47-d10NCM
Multiple Vulnerabilities are fixed in junos 12.2r9NCM
Vulnerabilities CVE-2015-3004 are fixed in junos 12.3x48-d10NCM
Multiple Vulnerabilities are fixed in junos 13.2r6NCM
Multiple Vulnerabilities are fixed in junos 13.3r5NCM
Multiple Vulnerabilities are fixed in junos 14.1r3NCM
Multiple Vulnerabilities are fixed in junos 14.2r1NCM
Improper Input Validation Vulnerability (CVE-2015-3004)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234