CVE-2018-0046 HIGH

CVE-2018-0046: Junos Space: Reflected Cross-site Scripting vulnerability in OpenNMS

Vendor Juniper Networks
Product Junos Space
Published October 10, 2018
Last update September 17, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions. This issue affects Juniper Networks Junos Space versions prior to 18.2R1.

Key dates

02Disclosure timeline

October 10, 2018 CVE published
September 17, 2024 Record updated