Multiple vulnerabilities have been resolved in the Juniper ATP 5.0.3 and 5.0.4 releases by fixing the vulnerabilities found during internal testing and updating the third party software packages included with Juniper ATP.
Important security issues resolved include:
The following software release have been updated to resolve this specific issue: 5.0.3 and all subsequent releases.
It is suggested to change any credentials after the upgrade to the fixed version.
The following software release have been updated to resolve this specific issue: 5.0.4 and all subsequent releases.
It is also recommended to purge the affected log files and/or change the passphrase after the upgrade.
It is suggested to change the Splunk credentials after the upgrade to the fixed version.
It is also recommended to change the device key after the upgrade.
These issues are being tracked as PR 1365584, 1365614, 1365976, 1365987, 1365676, 1365592, 1365609, 1365617, 1365601, 1365691, 1365606, 1365605, 1365985 and 1366352 which are visible on the Customer Support website.
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
There are no known workarounds for this issue, however, limiting access to only trusted administrators from trusted administrative networks or hosts would minimize the risk.