CVE-2014-2291
published 2014-03-14CVE-2014-2291: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
0.94%
56.6th percentile
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | ive_os | — | — |
| juniper | ive_os | — | — |
| juniper | ive_os | — | — |
| juniper | ive_os | — | — |
| juniper | junos_os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48mm-gw49-vvgc: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL
ghsa_unreviewed·2022-05-17
CVE-2014-2291 [LOW] CWE-79 GHSA-48mm-gw49-vvgc: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Juniper
CVE-2014-2291: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL
vendor_juniper·2014-03-14·CVSS 3.5
CVE-2014-2291 [LOW] CWE-79 CVE-2014-2291: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL
CVE-2014-2291: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Ivanti
Ivanti Security Advisory: CVE-2014-2291
vendor_ivanti·2014-03-14
CVE-2014-2291 CWE-79 Ivanti Security Advisory: CVE-2014-2291
Ivanti Security Advisory: CVE-2014-2291
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE IDs: CVE-2014-2291
CWEs: CWE-79
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/57375https://exchange.xforce.ibmcloud.com/vulnerabilities/91770https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10617http://secunia.com/advisories/57375https://exchange.xforce.ibmcloud.com/vulnerabilities/91770https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10617
2014-03-14
Published