CVE-2015-7322
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.
El Secure Meeting (Pulse Collaboration) en Pulse Connect Secure (anteriormente Juniper Junos Pulse) en versiones anteriores a 7.1R22.1, 7.4, 8.0 en versiones anteriores a 8.0R11 y 8.1 en versiones anteriores a 8.1R3 proporciona diferentes mensajes para los intentos para unirse a una reunión dependiendo del estado de la reunión, lo que permite a atacantes remotos enumerar los ids de reuniones válidos a través de una serie de peticiones.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-22 CVE Reserved
- 2015-10-05 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1033685 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://profundis-labs.com/advisories/CVE-2015-7322.txt | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40053 | 2016-12-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Juniper Search vendor "Juniper" | Pulse Connect Secure Search vendor "Juniper" for product "Pulse Connect Secure" | 7.1 Search vendor "Juniper" for product "Pulse Connect Secure" and version "7.1" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Pulse Connect Secure Search vendor "Juniper" for product "Pulse Connect Secure" | 7.4 Search vendor "Juniper" for product "Pulse Connect Secure" and version "7.4" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Pulse Connect Secure Search vendor "Juniper" for product "Pulse Connect Secure" | 8.0 Search vendor "Juniper" for product "Pulse Connect Secure" and version "8.0" | - |
Affected
| ||||||
Juniper Search vendor "Juniper" | Pulse Connect Secure Search vendor "Juniper" for product "Pulse Connect Secure" | 8.1 Search vendor "Juniper" for product "Pulse Connect Secure" and version "8.1" | - |
Affected
|