PT-2019-9606 · Citrix · Citrix Xenmobile Server

Publicado

2019-06-05

·

Atualizado

2019-09-11

·

CVE-2018-18571

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Citrix XenMobile Server versions 10.8.0 through 10.8.0 before Rolling Patch 6 Citrix XenMobile Server versions 10.9.0 through 10.9.0 before Rolling Patch 3
Description An Incorrect Access Control issue has been identified, allowing an attacker to impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Recommendations For Citrix XenMobile Server version 10.8.0, apply Rolling Patch 6 to resolve the issue. For Citrix XenMobile Server version 10.9.0, apply Rolling Patch 3 to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18571

Produtos afetados

Citrix Xenmobile Server