Vulnerabilities (CVE)

Filtered by vendor Juniper
Filtered by product J-web
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39565 1 Juniper 33 Ex2300, Ex2300-c, Ex3400 and 30 more 2026-01-22 N/A 8.8 HIGH
An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.  While an administrator is logged into a J-Web session or has previously logged in and subsequently logged out of their J-Web session, the attacker can arbitrarily execute commands on the target device with the other user's credentials. In the worst case, th ...

Show More