Reset Search
 

 

Article

SA40771 - 2017-07 Security Bulletin: Pulse Connect Secure (PCS) / Pulse Policy Secure (PPS): Cross Site Scripting Issue

« Go Back

Information

 
Product AffectedPulse Connect Secure (PCS) and Pulse Policy Secure (PPS)
Problem
Multiple cross site scripting issues has been found in the Pulse Connect Secure / Pulse Policy Secure device. The cause of this issue is due to incorrect validation of user input sent to the web server.  This does require the user to be logged in as administrator and not applicable end user portal.

These issues have been assigned the following CVEs:
  • CVE-2017-11194
  • CVE-2017-11196
  • CVE-2017-11195
  • CVE-2017-11193
Solution
This issue is resolved in the following PCS/PPS releases:  

July 12, 2017 - Initial document posted
August 3, 2017 - Fixed versions PCS 8.3R2.1, 8.2R8.2, 8.1R12.1 and 8.0R17 / PPS 5.4R2.1, 5.3R8.2 and 5.2R91 released
Workaround
Implementation
Related Links
CVSS Score
Risk Assessment
Acknowledgements
This vulnerability was discovered and responsibly reported to Pulse Secure by Corben Douglas (@sxcurity)
Alert TypeSA - Security Advisory
Risk LevelMedium
Attachment 1 
Attachment 2 
Legacy ID

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255