CVE-2015-7323: Low severity ivanti pulse connect secure vulnerability
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetings by leveraging a meeting id and meetingAppSun.jar.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7323?
CVE-2015-7323 has a high severity rating due to its potential to allow unauthorized access to meetings.
How do I fix CVE-2015-7323?
To fix CVE-2015-7323, upgrade Pulse Connect Secure to versions 7.1R22.1, 7.4, 8.0R11, or 8.1R3 or later.
Who is affected by CVE-2015-7323?
The vulnerability CVE-2015-7323 impacts users of Pulse Connect Secure versions prior to 7.1R22.1, 7.4, 8.0R11, and 8.1R3.
What type of attack does CVE-2015-7323 enable?
CVE-2015-7323 enables remote authenticated users to bypass access restrictions to log into arbitrary meetings.
Is there a workaround for CVE-2015-7323?
Unfortunately, there is no known workaround for CVE-2015-7323, and upgrading is the recommended action.