CVE-2016-1261

Description

J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.15

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-1256,CVE-2016-1261,CVE-2016-1264,CVE-2016-1267 are fixed in junos 12.1x44-d55NCM
Multiple Vulnerabilities are fixed in junos 12.1x46-d45NCM
Multiple Vulnerabilities are fixed in junos 12.1x47-d30NCM
Multiple Vulnerabilities are fixed in junos 12.3r11NCM
Vulnerabilities CVE-2016-1261,CVE-2016-1273,CVE-2017-2303 are fixed in junos 13.2x51-d40NCM
Vulnerabilities CVE-2015-7748,CVE-2016-1258,CVE-2016-1261,CVE-2016-1269 are fixed in junos 13.3r8NCM
Multiple Vulnerabilities are fixed in junos 14.1r6NCM
Vulnerabilities CVE-2015-7748,CVE-2016-1258,CVE-2016-1261,CVE-2016-4922 are fixed in junos 14.2r5NCM
Vulnerabilities CVE-2016-1261,CVE-2016-4923 are fixed in junos 15.1r3NCM
Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-1261)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234