First published: Thu May 26 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pulse Secure Pulse Connect Secure | =8.1 | |
Pulse Secure Pulse Connect Secure | =8.1r1.0 | |
Pulse Secure Pulse Connect Secure | =8.0 | |
Pulse Secure Pulse Connect Secure | =7.4 | |
Pulse Secure Pulse Connect Secure | =8.2 | |
Ivanti Connect Secure (ICS) VPN | =8.1 | |
Ivanti Connect Secure (ICS) VPN | =8.0 | |
Ivanti Connect Secure (ICS) VPN | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4789 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2016-4789, upgrade to Pulse Connect Secure version 8.2r1, 8.1r2, 8.0r9, or 7.4r13.4 or later.
CVE-2016-4789 affects users of Pulse Connect Secure versions prior to the specified patched versions.
CVE-2016-4789 impacts various versions of Pulse Secure and Ivanti Connect Secure.
Yes, CVE-2016-4789 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized access.