CVE-2019-0029: Juniper ATP: Splunk credentials are in logged in clear text
Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the Splunk server. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0029?
CVE-2019-0029 is considered a high severity vulnerability due to exposed credentials that allow unauthorized access to sensitive systems.
How do I fix CVE-2019-0029?
To fix CVE-2019-0029, you should upgrade your Juniper ATP software to version 5.0.3 or later.
Who is affected by CVE-2019-0029?
CVE-2019-0029 affects Juniper ATP 5.0 versions prior to 5.0.3, allowing local authenticated users to access sensitive credentials.
What are the risks of CVE-2019-0029?
The risks of CVE-2019-0029 include unauthorized access to the Splunk server, potentially leading to data breaches or malicious activities.
Is there a workaround for CVE-2019-0029?
There is no official workaround for CVE-2019-0029; upgrading to the patched version is necessary to mitigate the vulnerability.