CVE-2017-14935: Input Validation
Published Sep 29, 2017
·Updated
Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.
Affected Software
1 affected component
PulseSecure Pulse One On-premise=2.0.1649
Remediation
Event History
Sep 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14935?
CVE-2017-14935 is classified as a critical vulnerability due to its potential to expose sensitive information to unauthorized users.
2
How do I fix CVE-2017-14935?
To fix CVE-2017-14935, users should upgrade to Pulse Secure Pulse One On-Premise version 2.0.1650 or later.
3
What types of systems are affected by CVE-2017-14935?
CVE-2017-14935 affects Pulse Secure Pulse One On-Premise version 2.0.1649 and below.
4
What type of information can be obtained through CVE-2017-14935?
CVE-2017-14935 allows attackers to query and obtain sensitive information from the affected systems.
5
Is authentication required to exploit CVE-2017-14935?
No, CVE-2017-14935 can be exploited by remote users without authentication.