CVE-2021-0227
published 2021-04-22CVE-2021-0227: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allows an…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allows an attacker to cause Denial of Service (DoS) by sending certain crafted HTTP packets. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. When this issue occurs, web-management, NTP daemon (ntpd) and Layer 2 Control Protocol process (L2CPD) daemons might crash. This issue affects Juniper Networks Junos OS on SRX Series: 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R3-S2; 19.2 versions prior to 19.2R1-S5, 19.2R3; 19.3 versions prior to 19.3R3; 19.4 versions prior to 19.4R2-S1, 19.4R3; 20.1 versions prior to 20.1R1-S2, 20.1R2;
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | j-web | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 17.3 < 17.3R3-S9 | 17.3R3-S9 |
| juniper_networks | junos_os | >= 17.4 < 17.4R2-S11, 17.4R3-S2 | 17.4R2-S11, 17.4R3-S2 |
| juniper_networks | junos_os | >= 18.2 < 18.2R3-S5 | 18.2R3-S5 |
| juniper_networks | junos_os | >= 18.3 < 18.3R2-S4, 18.3R3-S3 | 18.3R2-S4, 18.3R3-S3 |
| juniper_networks | junos_os | >= 18.4 < 18.4R2-S5, 18.4R3-S4 | 18.4R2-S5, 18.4R3-S4 |
| juniper_networks | junos_os | >= 19.1 < 19.1R3-S2 | 19.1R3-S2 |
| juniper_networks | junos_os | >= 19.2 < 19.2R1-S5, 19.2R3 | 19.2R1-S5, 19.2R3 |
| juniper_networks | junos_os | >= 19.3 < 19.3R3 | 19.3R3 |
| juniper_networks | junos_os | >= 19.4 < 19.4R2-S1, 19.4R3 | 19.4R2-S1, 19.4R3 |
| juniper_networks | junos_os | >= 20.1 < 20.1R1-S2, 20.1R2 | 20.1R1-S2, 20.1R2 |
GHSA
GHSA-gg8j-57h5-7f75: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allo
ghsa_unreviewed·2022-05-24
CVE-2021-0227 [HIGH] CWE-119 GHSA-gg8j-57h5-7f75: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allo
An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allows an attacker to cause Denial of Service (DoS) by sending certain crafted HTTP packets. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. When this issue occurs, web-management, NTP daemon (ntpd) and Layer 2 Control Protocol process (L2CPD) daemons might crash. This issue affects Juniper Networks Junos OS on SRX Series: 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R3-S2; 19.2 versions prior to 19.2R1-
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) — CVE-2019-0227
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuoct2021 (OCT 2021)
Juniper
CVE-2021-0227: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allo
vendor_juniper·2021-04-22·CVSS 7.5
CVE-2021-0227 [HIGH] CWE-119 CVE-2021-0227: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allo
CVE-2021-0227: An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allows an attacker to cause Denial of Service (DoS) by sending certain crafted HTTP packets. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. When this issue occurs, web-management, NTP daemon (ntpd) and Layer 2 Control Protocol process (L2CPD) daemons might crash. This issue affects Juniper Networks Junos OS on SRX Series: 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R3-S2; 19.2 versions p
Oracle
Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) — CVE-2019-0227
Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) — CVE-2019-0227
Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujan2021 (JAN 2021)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-22
Published