CVE-2018-9849: Medium severity PulseSecure Pulse Connect Secure vulnerability
Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a crafted XML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9849?
CVE-2018-9849 is classified as a denial of service vulnerability that can lead to memory consumption and errors.
How do I fix CVE-2018-9849?
To fix CVE-2018-9849, upgrade Pulse Connect Secure to versions 8.1R14, 8.2R11, or 8.3R5 or later.
What software is affected by CVE-2018-9849?
CVE-2018-9849 affects Pulse Connect Secure versions prior to 8.1R14, 8.2R11, and 8.3R5.
What types of attacks can exploit CVE-2018-9849?
CVE-2018-9849 can be exploited by remote attackers using crafted XML documents to cause denial of service.
Is there a workaround for CVE-2018-9849 if I can't upgrade?
There are no known workarounds for CVE-2018-9849, so upgrading to a patched version is strongly recommended.