Unrated severityNVD Advisory· Published Mar 26, 2015· Updated May 6, 2026
CVE-2015-2682
CVE-2015-2682
Description
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.
Affected products
2cpe:2.3:a:citrix:command_center:5.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:command_center:5.2:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:command_center:5.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- packetstormsecurity.com/files/130928/Citrix-Command-Center-Configuration-Disclosure.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.securify.nl/advisory/SFY20140802/citrix_command_center_allows_downloading_of_configuration_files.htmlnvdExploit
- seclists.org/fulldisclosure/2015/Mar/126nvdMailing ListThird Party Advisory
- support.citrix.com/article/CTX200584nvdVendor Advisory
- www.securityfocus.com/bid/73309nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1031993nvdThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/36441/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.