iTnews Asia
  • Home
  • News
  • Security

Juniper Networks issues critical patches

Juniper Networks issues critical patches

Apache Commons Text and expat brought vulnerabilities with them.

By Richard Chirgwin on Apr 14, 2023 9:40AM

Juniper Networks has shipped fixes for critical bugs inherited from third-party software, as part of its first large shipment of patches in 2023.

In an advisory, Juniper reveals that its Secure Analytics product inherits an Apache Commons Text bug, CVE-2022-42889.

The bug means that applications using a vulnerable version of Apache Commons Text could be vulnerable to remote code execution (RCE).

“This issue affects Juniper Networks Security Threat Response Manager (STRM) versions prior to 7.5.0UP4 on JSA Series," Juniper’s advisory stated.

STRM 7.5.0UP4 and all subsequent releases use a patched version of Apache Commons Text.

In a separate advisory, Juniper said it has also updated the libexpat library it uses in its Junos OS operating system against 15 bugs, seven of which are rated critical (CVSS score of 9.8 in each case). The issue affects “all versions of Junos OS”, the advisory said.

The critical bugs include CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-25315, and CVE-2022-23852, all of which are integer overflows.

CVE-2022-25235 is an encoding validation error, and CVE-2022-25236 “allows attackers to insert namespace-separator characters into namespace URIs”.

Fixes have been shipped for all affected Junos OS build series.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apache juniper networks libexpat security

Related Articles

  • Beware the pitfalls of using a ‘DIY security’ approach
  • AI transforms cyberattacks, but human trust remains the weakest link
  • How severe will ransomware attacks become in 2026?
  • Identity is now the new cybersecurity battlefield
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Beware the pitfalls of using a ‘DIY security’ approach

Beware the pitfalls of using a ‘DIY security’ approach

AI transforms cyberattacks, but human trust remains the weakest link

AI transforms cyberattacks, but human trust remains the weakest link

Zuellig Pharma launches Asia's first healthcare data exchange platform

Zuellig Pharma launches Asia's first healthcare data exchange platform

Toyota's Indian unit warns of a possible customer data breach

Toyota's Indian unit warns of a possible customer data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.