#VU27030 Path traversal in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2019-11508
Published: April 20, 2020 / Updated: April 20, 2020
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing file uploads within Network File Share (NFS) feature of Pulse Connect Secure. A remote authenticated user can can send a specially crafted HTTP request and upload dangerous files to arbitrary locations on the system.