Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jean-Frédéric Gauron

Researcher fromGoSecure
#21684of 53,635
11Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-20049
6.1
2020-09-29
Pulse · Pulse Policy Secure · CVE-2020-8238
**Name of the Vulnerable Software and Affected Versions** Pulse Connect Secure and Pulse Policy Secure versions prior to 9.1R8.2 **Description** A vulnerability in the authenticated user web interface could allow attackers to conduct Cross-Site Scripting (XSS). **Recommendations** For Pulse Connect Secure and Pulse Policy Secure versions prior to 9.1R8.2, update to version 9.1R8.2 or later to resolve the issue.
PT-2020-20064
4.9
2020-09-29
Pulse · Pulse Connect Secure · CVE-2020-8256
**Name of the Vulnerable Software and Affected Versions** Pulse Connect Secure versions prior to 9.1R8.2 **Description** A vulnerability in the Pulse Connect Secure admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability. **Recommendations** For versions prior to 9.1R8.2, update to version 9.1R8.2 or later to resolve the issue.