VYPR

ShareFile

by Citrix Systems

CVEs (5)

  • CVE-2020-8982HigMay 7, 2020
    risk 0.51cvss 7.5epss 0.27

    An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or…

  • CVE-2021-22932HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.00

    An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously…

  • CVE-2020-8983HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.05

    An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile,…

  • CVE-2019-7217HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.02

    Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.

  • CVE-2019-7218MedMay 13, 2019
    risk 0.38cvss 5.9epss 0.01

    Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase…