PT-2018-10033 · Citrix+1 · Citrix Xenmobile Server+1

Publicado

2018-05-23

·

Atualizado

2018-06-25

·

CVE-2018-10654

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix XenMobile Server versions 10.7 before RP3 and 10.8 before RP2
Description The issue concerns a Java Deserialization Vulnerability in the Hazelcast Library used by Citrix XenMobile Server.
Recommendations For versions 10.7 before RP3, update to RP3 or later to resolve the issue. For versions 10.8 before RP2, update to RP2 or later to resolve the issue.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10654

Produtos afetados

Citrix Xenmobile Server
Hazelcast Library