Multiple known vulnerabilities exist in CentOS 6.8, shipped with Junos Space Policy Enforcer prior to version 22.1R1.
Policy Enforcer is a component of the Junos Space Security Director user interface, integrated with Sky ATP to provide centralized threat management and monitoring for software-defined secure networks.
These issues affect all versions of Juniper Networks Junos Space Policy Enforcer prior to 22.1R1.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
The version of CentOS shipped with the Policy Enforcer component of Junos Space Security Director has been upgraded from CentOS 6.8 to 7.9 in version 22.1R1.
The following software releases have been updated to resolve this specific issue: Junos Space Security Director Policy Enforcer 22.1R1 and all subsequent releases.
Note: Upgrading Policy Enforcer also requires a compatible version of Junos Space Security Director.
This issue is being tracked as 1653068.
2022-07-13: Initial publication