On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

Published at
2019-01-15
1097 days ago
Modified
2019-01-15
1097 days ago
2019
Year
The year of the turtle

https://kb.juniper.net/JSA10918

CONFIRM:https://kb.juniper.net/JSA10918

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2019-0004"
	},
	"Notes": {
		"Note": [
			{
				"_text": "On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3."
			},
			{
				"_text": "2019-01-15"
			},
			{
				"_text": "2019-01-15"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2019-0004"
	},
	"References": {
		"Reference": {
			"URL": {
				"_text": "https://kb.juniper.net/JSA10918"
			},
			"Description": {
				"_text": "CONFIRM:https://kb.juniper.net/JSA10918"
			}
		}
	}
}