Citrix
Citrix Xenmobile Server: vulnerabilidades y CVE
Citrix Xenmobile Server tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-44519 | Alta (8.8) | 2.8% | — | 19 abr 2022 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution. |
| CVE-2022-26151 | Alta (7.2) | 7.3% | — | 13 abr 2022 | Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. |
| CVE-2021-44520 | Alta (8.8) | 5.7% | — | 13 abr 2022 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges. |
| CVE-2020-8253 | Alta (7.5) | 1.7% | — | 18 sept 2020 | Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to… |
| CVE-2020-8212 | Crítica (9.8) | 1.6% | — | 17 ago 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged… |
| CVE-2020-8211 | Crítica (9.8) | 1.5% | — | 17 ago 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection. |
| CVE-2020-8210 | Alta (7.5) | 1.5% | — | 17 ago 2020 | Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses… |
| CVE-2020-8209 | Alta (7.5) | 49% | — | 17 ago 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the… |
| CVE-2020-8208 | Media (6.1) | 0.96% | — | 17 ago 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site… |
| CVE-2018-18571 | Crítica (9.1) | 2.6% | — | 5 jun 2019 | An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any… |
| CVE-2018-18014 | Media (4.8) | 0.48% | — | 24 oct 2018 | * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the… |
| CVE-2018-18013 | Alta (7.8) | 2.9% | — | 24 oct 2018 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into… |
| CVE-2018-10654 | Alta (8.1) | 1.2% | — | 23 may 2018 | There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10653 | Crítica (9.8) | 6.8% | — | 23 may 2018 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10652 | Alta (7.5) | 1.2% | — | 23 may 2018 | There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10651 | Media (6.1) | 0.73% | — | 23 may 2018 | There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10650 | Alta (7.8) | 0.82% | — | 23 may 2018 | There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10649 | Media (6.1) | 0.67% | — | 23 may 2018 | There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10648 | Crítica (9.8) | 1.2% | — | 23 may 2018 | There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2017-9231 | Alta (7.5) | 1.8% | — | 16 jun 2017 | XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors. |
| CVE-2016-6877 | Media (5.3) | 1.3% | — | 5 may 2017 | Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis… |
| CVE-2016-2789 | Media (6.1) | 0.80% | — | 7 abr 2016 | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or… |
📰 Noticias relacionadas
Otros productos de Citrix
Xenserver · 55Netscaler Gateway · 45Netscaler Application Delivery Controller · 39Netscaler Gateway Firmware · 31Application Delivery Controller Firmware · 30Netscaler Application Delivery Controller Firmware · 29Gateway · 19Sd-wan · 18Netscaler Sd-wan · 16Gateway Firmware · 15Access Gateway · 14Workspace · 14