Reset Search
 

 

Article

SA43018 - 2018-01 Out-Of-Cycle Advisory: Pulse Connect Secure (PCS) / Pulse Policy Secure (PPS): Cross Site Scripting Issue

« Go Back

Information

 
Product AffectedPulse Connect Secure (PCS) and Pulse Policy Secure (PPS)
Problem
A cross site scripting issue with custompage.cgi has been found in the Pulse Connect Secure / Pulse Policy Secure device. The cause is due to one of the URL parameters not sanitized. This does require the user to be logged in to the administrator portal and not applicable to end user portal.

CVE-2017-17947 has been assigned to it. 
Solution
This issue is resolved in the following PCS/PPS releases:   Version history:

January 02, 2018 - Fixed versions PCS 8.3R2.1, 8.2R8.2, 8.1R12.1 and 8.0R17 / PPS 5.4R2.1, 5.3R8.2 and 5.2R91 released
Workaround
Implementation
Related Links
CVSS Score6.1
Risk Assessment
Acknowledgements
This vulnerability was discovered and responsibly reported to Pulse Secure by Brian Hyde.
Alert TypeSA - Security Advisory
Risk LevelMedium
Attachment 1 
Attachment 2 
Legacy ID

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255