CVE-2019-0004

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
15/01/2019
Last modified:
29/09/2020

Description

On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:advanced_threat_prevention:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.3 (excluding)
cpe:2.3:h:juniper:atp400:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:atp700:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools