PT-2016-3846 · Citrix · Citrix Command Center

Published

2016-04-14

·

Updated

2019-02-13

·

CVE-2015-7999

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix Command Center versions prior to 5.1 Build 36.7 Citrix Command Center versions prior to 5.2 Build 44.11
Description The issue allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors due to multiple SQL injection vulnerabilities in the Administration Web UI servlets.
Recommendations For Citrix Command Center versions prior to 5.1 Build 36.7, update to version 5.1 Build 36.7 or later. For Citrix Command Center versions prior to 5.2 Build 44.11, update to version 5.2 Build 44.11 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7999

Affected Products

Citrix Command Center