Reset Search
 

 

Article

JSA10490 - 2011-09 Security Bulletin: Pulse Connect Secure (PCS): Cross Site Scripting Issues

« Go Back

Information

 
Product AffectedPCS: SA 500, SA 700, SA 2000, SA 2500, SA 4000, SA 4500, SA 6000, SA 6500, SA 4000 FIPS, SA 6000 FIPS, SA 4500 FIPS, SA 6500 FIPS, MAG2600, MAG4610, MAG-SM160, MAG-SM360
Problem
Cross Site Scripting vulnerabilities found and fixed through a combination of internal and external proactive security testing:
- Cross Site Scripting issue found in Secure Meeting web page.
- Cross Site Scripting issue found in Network Connect web page.
- Cross Site Scripting issue found in Terminal Access web page.
- Cross Site Scripting issue found in Session Manager web page.

Pulse Secure would like to acknowledge n.runs AG for reporting one of the above issues.
Solution
The following PCS software releases have a fix for these issues, PCS: 6.5R10; 7.0R7, 7.1R4 or higher.
We recommend upgrading your PCS software to resolve this security vulnerability.

Note: Pulse Secure policy is to only publish fixes for release that have not yet reached End-of-Engineering. These issues were reported prior to 6.5 reaching its End-of-Engineering date so the fixes for this release are published in this Security Bulletin.


 
Workaround
None.
Implementation
Related Links
Patched Software Release Service Packages are available at Pulse Secure Licensing and Download Center: https://my.pulsesecure.net. Documentation links to the relevant software’s are also available at Pulse Secure Licensing and Download Center.
CVSS Score5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)
Risk AssessmentYou can gain unauthorized access to protected resources.
Acknowledgements
Alert TypePSN - Product Support Notification
Risk LevelMedium
Attachment 1 
Attachment 2 
Legacy IDPSN-2011-08-344, JSA10490

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255