VYPR

Virtual Traffic Manager

by Pulsesecure

CVEs (3)

  • CVE-2021-31922HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolved in 21.1, 20.3R1, 20.2R1, 20.1R2, 19.2R4, and 18.2R3.

  • CVE-2018-20306MedDec 20, 2018
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and credentials. Affected…

  • CVE-2018-20307MedDec 20, 2018
    risk 0.28cvss 4.3epss 0.01

    Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.