PT-2019-9606 · Citrix · Citrix Xenmobile Server
Publicado
2019-06-05
·
Atualizado
2019-09-11
·
CVE-2018-18571
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Citrix XenMobile Server versions 10.8.0 through 10.8.0 before Rolling Patch 6
Citrix XenMobile Server versions 10.9.0 through 10.9.0 before Rolling Patch 3
Description
An Incorrect Access Control issue has been identified, allowing an attacker to impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Recommendations
For Citrix XenMobile Server version 10.8.0, apply Rolling Patch 6 to resolve the issue.
For Citrix XenMobile Server version 10.9.0, apply Rolling Patch 3 to resolve the issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Xenmobile Server