SA and UAC use ActiveX controls or Java applets to install and launch client software from a web browser. Due to the inherent problems with using ActiveX and Java applet, users can unknowingly connect to untrusted/rogue SA and UAC and components can be launched without their knowledge.
The Trusted Server List (also known as allowlist) is a new feature added to address the issue. Due to the behavioral change and impact of the end user environment, Juniper has added this feature in 6.5 IVE OS release and higher and UAC 3.1 release and higher. Information regarding the Juniper Network fix policy for Security Issues can be found at KB16765 [juniper.net] "In which releases are vulnerabilities fixed?"
None
2010-06-09: Initial Publication 2020-11-06: Updated terminology