"value":"On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3."
"value":"CWE-532 - Information Exposure Through Log Files"
}
]
}
]
},
"references":{
"reference_data":[
{
"name":"https://kb.juniper.net/JSA10918",
"refsource":"CONFIRM",
"url":"https://kb.juniper.net/JSA10918"
}
]
},
"solution":[
{
"lang":"eng",
"value":"The following software release have been updated to resolve this specific issue: 5.0.3 and all subsequent releases.\nIt is also recommended to change the device key after the upgrade."
}
],
"source":{
"advisory":"JSA10918",
"defect":[
"1365691"
],
"discovery":"INTERNAL"
},
"work_around":[
{
"lang":"eng",
"value":"There are no known workarounds for this issue, however limit the access to only trusted administrators from trusted administrative networks or hosts would minimize the risk."