CVE-2022-21826
- EPSS 34.52%
- Veröffentlicht 30.09.2022 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:45:30
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends...
CVE-2021-44720
- EPSS 2.62%
- Veröffentlicht 12.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:27
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can es...
CVE-2021-22965
- EPSS 11.33%
- Veröffentlicht 19.11.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:02
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.
CVE-2021-22938
- EPSS 3.93%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.
CVE-2021-22937
- EPSS 7.49%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.
CVE-2021-22936
- EPSS 0.15%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
CVE-2021-22935
- EPSS 3.93%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
CVE-2021-22934
- EPSS 4.38%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.
CVE-2021-22933
- EPSS 6.31%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:57
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
- EPSS 31.77%
- Veröffentlicht 27.05.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:50:53
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by...