Executive brief
Ivanti Pulse Connect Secure (formerly Pulse Secure) contains an arbitrary file read vulnerability due to improper limitation of a pathname to a restricted directory. An unauthenticated remote attacker can exploit this by sending a specially crafted URI to access sensitive files on the system.
Affected products
- Ivanti (Pulse Secure) Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4
Timeline
- 2019-04-24: advisory: Initial vendor advisory SA44101 published by Pulse Secure
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed: NVD publication date