Multiple vulnerabilities using various attack methods have been addressed in Junos Space 15.1R3 and 15.2R1. Exploitation of these vulnerabilities may potentially allow a remote unauthenticated network based attacker with access to Junos Space to execute arbitrary code on Junos Space or gain access to devices managed by Junos Space.
OpenJDK runtime was upgraded to 1.7.0 update 85 (from 1.7.0 update 79) which resolves the following vulnerabilities:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
The following software releases have been updated to resolve this specific issue: Junos Space 15.1R3, 15.2R1, and all subsequent releases. This issues are being tracked as PR 1134808, 960740, 975433, 975434, 975459, 975460, 975514, 983937, 983943, 983944, 983948, 983953, 983956, 999051, 1114551 and are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
2016-04-13: Initial publication 2016-04-21: Reformatted Problem section to clarify the consolidated set of privilege escalation vulnerabilities 2016-05-26: Added 15.1R3 fixed release 2016-09-07: Corrected the name of Java runtime environment used by Space.