A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601