A local user privilege escalation issue has been found in the Junos WebApp Secure product. This issue could allow a local user with shell access the ability to escalate their privileges to root.Juniper SIRT is not aware of any malicious exploitation of this vulnerability.No other Juniper Networks products or platforms are affected by this issue.This issue is known as CVE-2013-2094

 Software updates to Junos WebApp Secure have been released to resolve this issue. The releases containing the fix is: 5.1.3-30, 5.1.3-4, and 5.1.3-24. Note: the Heartbleed fix and the fix for this issue is supplied in 5.1.3-30.KB16765 – “In which releases are vulnerabilities fixed?” describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.

 There is no workaround for this issue. An upgrade to a fixed version of software is required for the fix.

Leave a Reply