Junos Space release 13.3R1.8 addresses multiple vulnerabilities in prior releases with updated third party software components. The following is a list of software upgraded and vulnerabilities resolved:
Apache HTTP Server upgraded to 2.2.25 which resolves:
Oracle MySQL server upgraded to 5.5.34 which resolves:
OpenJDK Runtime Environment was upgraded to 7u45 which resolves a number of vulnerabilities that affect server deployments of Java including but not limited to:
RedHat JBoss application server upgraded to 7.1 resolves:
The MySQL server used in Junos Space prior to 13.3R1.8 has a user account with a hardcoded password. If the firewall that is enabled by default in Junos Space is disabled for any reason, then information stored by Junos Space on MySQL database could be accessed over the network, leading to an information disclosure vulnerability. Information in the MySQL database can be misused to get complete control of the system or devices managed by Junos Space. MySQL server configuration in 13.3R1.8 has been hardened and restricted to resolve this vulnerability. This issue is assigned CVE-2014-3413. CVSS v2 base score for this vulnerability is 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C).
This issue is fixed in Junos Space 13.3R1.8 and all subsequent releases.
Junos Space releases can be obtained from: http://www.juniper.net/support/downloads/?p=space#sw Modification History:
14 May 2014: Initial release. 5 Nov 2014: Included RESTEasy vulnerabilities CVE-2011-5245 and CVE-2012-0818. 7 Sep 2016: Corrected the name of Java Runtime Environment used by Space.
These vulnerabilities can be mitigated by enabling the firewall on Junos Space and limiting access only from trusted hosts.
Juniper SIRT would like to acknowledge and thank Tenable Network Security for responsibly reporting CVE-2014-3413 vulnerability.