CVE-2015-7322: Infoleak
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7322?
CVE-2015-7322 is considered a high severity vulnerability due to its potential for remote enumeration attacks.
How do I fix CVE-2015-7322?
To mitigate CVE-2015-7322, upgrade Pulse Connect Secure to the latest version as specified in the security advisories.
What versions are affected by CVE-2015-7322?
CVE-2015-7322 affects Pulse Connect Secure versions prior to 7.1R22.1, 7.4, 8.0R11, and 8.1R3.
What kind of attack does CVE-2015-7322 allow?
CVE-2015-7322 allows remote attackers to enumerate meeting statuses within Pulse Collaboration.
Who is impacted by CVE-2015-7322?
Organizations using vulnerable versions of Pulse Connect Secure for remote collaboration services are impacted by CVE-2015-7322.