First published: Thu Dec 20 2018(Updated: )
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pulsesecure Virtual Traffic Manager | =9.9 | |
Pulsesecure Virtual Traffic Manager | =9.9-r1 | |
Pulsesecure Virtual Traffic Manager | =10.4 | |
Pulsesecure Virtual Traffic Manager | =17.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20307 is a vulnerability that affects Pulse Secure Virtual Traffic Manager versions prior to 9.9r2 and 10.4r1.
CVE-2018-20307 allows a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation in Pulse Secure Virtual Traffic Manager.
The severity of CVE-2018-20307 is medium with a CVSS score of 4.3.
To fix CVE-2018-20307, users should update to Pulse Secure Virtual Traffic Manager version 9.9r2 or 10.4r1.
More information about CVE-2018-20307 can be found at the following link: [Pulse Secure Security Advisories - SA43730](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730)