A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected products are: Juniper Networks Service Insight versions from 15.1R1, prior to 18.1R1. Service Now versions from 15.1R1, prior to 18.1R1.
Solution:
Workaround:
Storing a password in plaintext may result in a system compromise.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10921 | vendor advisory |
https://kb.juniper.net/KB27572 | release notes vendor advisory |
http://www.securityfocus.com/bid/107885 | vdb entry third party advisory |