5
CVSSv2

CVE-2015-7322

Published: 05/10/2015 Updated: 08/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) prior to 7.1R22.1, 7.4, 8.0 prior to 8.0R11, and 8.1 prior to 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote malicious users to enumerate valid meeting ids via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

juniper pulse connect secure 7.1

juniper pulse connect secure 7.4

juniper pulse connect secure 8.0

juniper pulse connect secure 8.1

Exploits

Junos Pulse Secure Meeting version 805 allows an attacker to enter "secure" meetings without knowledge of the password and the invitation link using the java fat client (meetingAppSunjar) ...