CVE-2018-20307: Pulse Secure Virtual Traffic Manager

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.

Affected products

  • Pulse Secure Virtual Traffic Manager: version 9.9 only; version 10.4 only; version 17.2 only

Published 2018-12-20. Last modified 2026-06-17.