CVE Published: 15/01/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2019 Source: juniper |
Vendor: Juniper Networks |
Product: Juniper ATP Status : PUBLISHED
CVE-2019-0026 Description
A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.