Multiple vulnerabilities have been addressed in Junos Space 15.1R1 release. These include cross site scripting (XSS), SQL injection and command injection vulnerabilities. These vulnerabilities may potentially allow a remote unauthenticated network based attacker with access to Junos Space to execute arbitrary code on Junos Space. These vulnerabilities were found during internal product testing. These issues have been assigned CVE-2015-7753.
OpenJDK runtime was upgraded to 1.7.0 update_79 which resolves:
Following vulnerability was resolved in OpenNMS software included with Junos Space:
KVM Package was upgraded to kvm-83-273.el5.centos.x86_64.rpm which resolves the following vulnerability:
Mozilla NSS Package was upgraded to nss-3.18.0-6.el5_11 which resolves the following vulnerability:
Apache HTTP Server was upgraded to 2.2.31 resolving the following issues:
MySQL was upgraded to 5.6.23 which resolves the following vulnerabilities that may pose a risk to MySQL as used in Junos Space:
The following software releases have been updated to resolve these issues: Junos Space 15.1R1, and all subsequent releases. CVE-2015-0975 is being tracked as PR 1060097. CVE-2015-3209 is being tracked as PR 1067419. OpenJDK JRE upgrade is being tracked as PR 987851. Apache upgrade is being tracked as PR 987853. MySQL upgrade is being tracked as PR 987852. These PRs are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
How to obtain fixed software: Junos Space Releases are available at http://www.juniper.net/support/downloads/?p=space#sw .
As a workaround, use access lists or firewall filters to limit access to the device, so that it can only be accessed from trusted hosts which are restricted from accessing potentially hazardous sites and services. Restrict access to only highly trusted administrators. To mitigate XSS vulnerabilities with Junos Space use a dedicated client and dedicated web browser that is not used to access other sites.
2015-10-14: Initial publication 2016-09-07: Corrected the name of Java Runtime Environment used by Junos Space.