CVE-2015-7322

T

he Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:juniper:pulse_connect_secure:7.1:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:7.4:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:8.0:*:*:*:*:*:*:*
cpe:2.3:a:juniper:pulse_connect_secure:8.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:36

Type Values Removed Values Added
References () http://www.securitytracker.com/id/1033685 - () http://www.securitytracker.com/id/1033685 -
References () https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40053 - Vendor Advisory () https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40053 - Vendor Advisory
References () https://profundis-labs.com/advisories/CVE-2015-7322.txt - Exploit () https://profundis-labs.com/advisories/CVE-2015-7322.txt - Exploit

Information

Published : 2015-10-05 15:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-7322

Mitre link : CVE-2015-7322

CVE.ORG link : CVE-2015-7322


JSON object : View

Products Affected
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor