- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-19-2025 05:42 AM
Hello all,
Our customer is currently using PA-3220 running PAN-OS 11.1.
During their recent vulnerability scan, the following CVEs were reported that jQuery used on the Web management interface;
CVE-2018-8046
CVE-2007-6758
Questions:
1. Do these vulnerabilities actually affect? Or false positive from their vulnerability scanner?
2. What is the purpose of using jQuery in the Web management interface?
Thank you for your support.
Shinichi
08-20-2025 09:44 AM
Hello,
Run the scans again but slow them down. See if you get the same results. Sometimes fast unauthenticated scans give false positives.
Regards,
08-25-2025 04:20 AM
Hi OtakarKlier,
Thank you for your reply.
Unfortunately, they said it would be difficult to run a vulnerability scan again.
Since those CVEs are not currently listed in the "Palo Alto Networks Security Advisories" information, I have concluded that they are not affected.
Thank you.
Shinichi
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

