Multiple vulnerabilities have been resolved in Junos Space 15.2R2 release.
In addition to the above a vulnerability in Apache Commons Collections that can potentially allow remote code execution during object de-serialization is fixed by upgrading Apache Commons Collections to 3.2.2. This vulnerability is not exposed and is not exploitable on Junos Space, however the underlaying library is upgraded to eliminate all risks. Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
Many of these issues were found during internal product testing.
These issues have been resolved in Junos Space 15.2R2 and all subsequent releases. These issues are being tracked as 954495, 975358, 975426, 975445, 975447, 975457, 975466, 975472, 975473, 975474, 975491, 975502, 975506, 975509, 975510, 975516, 975518, 975530, 975534, 983931, 983945, 983960, 983964, 1049736, 1049737, 1105605, 1138099, 1164153, 1165549 and are visible on the Customer Support website.
2016-10-12: Initial publication