Vulnerabilities > Ivanti

DATE CVE VULNERABILITY TITLE RISK
2019-04-26 CVE-2019-11539 OS Command Injection vulnerability in multiple products
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
network
low complexity
pulsesecure ivanti CWE-78
7.2
2019-04-26 CVE-2019-11538 Link Following vulnerability in Ivanti Connect Secure
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS problem could allow an authenticated attacker to access the contents of arbitrary files on the affected device.
network
low complexity
ivanti CWE-59
7.7
2019-04-12 CVE-2019-11213 Session Fixation vulnerability in multiple products
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573.
network
high complexity
pulsesecure ivanti CWE-384
8.1
2019-04-05 CVE-2019-10885 Permissions, Privileges, and Access Controls vulnerability in Ivanti Workspace Control
An issue was discovered in Ivanti Workspace Control before 10.3.90.0.
local
low complexity
ivanti CWE-264
7.8
2018-10-15 CVE-2018-15593 Unspecified vulnerability in Ivanti Workspace Control
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace.
local
low complexity
ivanti
7.8
2018-10-15 CVE-2018-15592 Improper Privilege Management vulnerability in Ivanti Workspace Control
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace.
local
low complexity
ivanti CWE-269
7.8
2018-10-15 CVE-2018-15591 Exposure of Resource to Wrong Sphere vulnerability in Ivanti Workspace Control
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace.
local
low complexity
ivanti CWE-668
7.8
2018-10-15 CVE-2018-15590 Unspecified vulnerability in Ivanti Workspace Control
An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured.
local
low complexity
ivanti
5.5
2018-09-06 CVE-2018-6320 Improper Input Validation vulnerability in multiple products
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
network
low complexity
pulsesecure ivanti CWE-20
critical
9.8
2018-09-06 CVE-2018-14366 Open Redirect vulnerability in multiple products
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
network
low complexity
pulsesecure ivanti CWE-601
6.1