CVE Vulnerabilities

CVE-2019-11541

Published: Apr 26, 2019 | Modified: Feb 27, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

Affected Software

Name Vendor Start Version End Version
Connect_secure Ivanti 8.2 (including) 8.2 (including)
Connect_secure Ivanti 8.3 (including) 8.3 (including)
Pulse_connect_secure Pulsesecure 8.2r1.0 (including) 8.2r1.0 (including)
Pulse_connect_secure Pulsesecure 8.2r1.1 (including) 8.2r1.1 (including)
Pulse_connect_secure Pulsesecure 8.2r2.0 (including) 8.2r2.0 (including)
Pulse_connect_secure Pulsesecure 8.2r3.0 (including) 8.2r3.0 (including)
Pulse_connect_secure Pulsesecure 8.2r3.1 (including) 8.2r3.1 (including)
Pulse_connect_secure Pulsesecure 8.2r4.0 (including) 8.2r4.0 (including)
Pulse_connect_secure Pulsesecure 8.2r4.1 (including) 8.2r4.1 (including)
Pulse_connect_secure Pulsesecure 8.2r5.0 (including) 8.2r5.0 (including)
Pulse_connect_secure Pulsesecure 8.2r5.1 (including) 8.2r5.1 (including)
Pulse_connect_secure Pulsesecure 8.2r6.0 (including) 8.2r6.0 (including)
Pulse_connect_secure Pulsesecure 8.2r7.0 (including) 8.2r7.0 (including)
Pulse_connect_secure Pulsesecure 8.2r7.1 (including) 8.2r7.1 (including)
Pulse_connect_secure Pulsesecure 8.2rx (including) 8.2rx (including)
Pulse_connect_secure Pulsesecure 8.3rx (including) 8.3rx (including)
Pulse_connect_secure Pulsesecure 9.0r1 (including) 9.0r1 (including)
Pulse_connect_secure Pulsesecure 9.0r2 (including) 9.0r2 (including)
Pulse_connect_secure Pulsesecure 9.0r2.1 (including) 9.0r2.1 (including)
Pulse_connect_secure Pulsesecure 9.0r3 (including) 9.0r3 (including)
Pulse_connect_secure Pulsesecure 9.0r3.1 (including) 9.0r3.1 (including)
Pulse_connect_secure Pulsesecure 9.0r3.2 (including) 9.0r3.2 (including)
Pulse_connect_secure Pulsesecure 9.0rx (including) 9.0rx (including)

References