3.5
CVSSv2

CVE-2015-7323

Published: 05/10/2015 Updated: 08/12/2016
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) prior to 7.1R22.1, 7.4, 8.0 prior to 8.0R11, and 8.1 prior to 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetings by leveraging a meeting id and meetingAppSun.jar.

Vulnerable Product Search on Vulmon Subscribe to Product

juniper pulse connect secure 8.0

juniper pulse connect secure 8.1

juniper pulse connect secure 7.1

juniper pulse connect secure 7.4

Exploits

Junos Pulse Secure Meeting version 805 allows an attacker to enter "secure" meetings without knowledge of the password and the invitation link using the java fat client (meetingAppSunjar) ...