CVE-2020-15352: Ivanti Connect Secure
High severity, CVSS 7.2. EPSS: 3.2% chance of exploitation in the next 30 days.
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Affected products
- Ivanti Connect Secure: version 9.1 only
- Ivanti Policy Secure: version 9.1 only
- Pulse Secure Pulse Connect Secure: up to and including 9.0
- Pulse Secure Pulse Policy Secure: up to and including 9.0
Published 2020-10-27. Last modified 2026-06-17.