CVE-2014-2291
Juniper Junos Pulse Secure Access Service <8.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Scores
EPSS
0.0021
EPSS Percentile
43.1%
Details
CWE
CWE-79
Status
published
Products (5)
juniper/ive_os
juniper/ive_os
juniper/ive_os
juniper/ive_os
n/a/n/a
Published
Mar 14, 2014
Tracked Since
Feb 18, 2026