CVE-2021-22935
16.08.2021, 19:15
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
| Vendor | Product | Version |
|---|---|---|
| ivanti | connect_secure | 9.1 |
| ivanti | connect_secure | 9.1:r1.0 |
| ivanti | connect_secure | 9.1:r10.0 |
| ivanti | connect_secure | 9.1:r11.0 |
| ivanti | connect_secure | 9.1:r2.0 |
| ivanti | connect_secure | 9.1:r3.0 |
| ivanti | connect_secure | 9.1:r4.0 |
| ivanti | connect_secure | 9.1:r5.0 |
| ivanti | connect_secure | 9.1:r6.0 |
| ivanti | connect_secure | 9.1:r7.0 |
| ivanti | connect_secure | 9.1:r8.0 |
| ivanti | connect_secure | 9.1:r9.0 |
| pulsesecure | pulse_connect_secure | 𝑥 < 9.1 |
𝑥
= Vulnerable software versions