Multiple vulnerabilities in Juniper Secure Analytics (JSA) and Security Threat Response Manager (STRM) software have been resolved with updated third party software components.
CVE-2014-0411 A TLS timing vulnerability in IBM Runtime Environment, Java Technology Edition, Version 6 and 7 affects STRM/JSA 2013 [juniper.net].2 releases prior to 2013.2R7. This may allow remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake. STRM/JSA 2014 [juniper.net].2 and later releases do not have this problem.
CVE-2014-0114 A ClassLoader manipulation vulnerability in Apache Struts affects STRM/JSA 2012 [juniper.net].1 releases prior to 2012.1R7 and 2013.2 releases prior to 2013.2R8. This may allow a remote attacker to execute arbitrary code on the system. STRM/JSA 2014 [juniper.net].2 and later releases do not have this problem.
STRM/JSA 2013 [juniper.net].2 releases prior to 2013.2R8 and 2014.2R2 are affected by the following Apache Tomcat and Apache Xalan-Java vulnerabilities:
STRM 2012.1 releases prior to 2012.1R8 are affected by the following PostgreSQL vulnerabilities:
STRM 2012.1 releases prior to 2012.1R8, STRM/JSA 2013 [juniper.net].2 releases prior to 2013.2R8 and JSA 2014 [juniper.net].2R2 are vulnerable to the following Apache and OpenSSL vulnerabilities:
JSA 2012 [juniper.net].1R8, 2013.2R8, 2014.2R3 or later releases completely resolve all the vulnerabilities mentioned above.
Specifically:
How to obtain fixed software: JSA and STRM Software Releases are available at http://www.juniper.net/support/downloads/ .
Use access lists or firewall filters to limit access to the JSA/STRM device only from trusted hosts.