US Cert - "US Computer Emergency Readiness Team" issued a vulnerability advisory on clientless SSL VPN's including Juniper. http://www.kb.cert.org/vuls/id/261869
Just curious if anyone has taken a look at it and had any thoughts on it. It seems to me that while it does outline a potential threat it is very easily dealt with and really not that much of an issue.
I have had a few calls from very security concerned customers already on this one and was wondering what my fellow SSL geeks think about this.
This Juniper KB has a few remediations to the vulnerability: