Medium severity6.1NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2020-8238
CVE-2020-8238
Description
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
Affected products
31cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:ivanti:connect_secure:9.1:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r8:*:*:*:*:*:*
cpe:2.3:a:ivanti:policy_secure:9.1:-:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:ivanti:policy_secure:9.1:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r7:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r8.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:9.1:r8:*:*:*:*:*:*
cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*range: <=9.0
- (no CPE)range: <9.1R8.2
cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pulsesecure:pulse_policy_secure:*:*:*:*:*:*:*:*range: <=9.0
- (no CPE)range: <9.1R8.2
- Range: Fixed in 9.1R8.2
Patches
Vulnerability mechanics
References
2- www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/nvdExploitThird Party Advisory
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588nvdVendor Advisory
News mentions
0No linked articles in our index yet.