On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
Solution:
Workaround:
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10918 | vendor advisory |