Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown

Juniper ATP: API and device keys are logged in a world-readable permissions file

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.