VYPR

Xenmobile Server

by Citrix Systems

CVEs (20)

  • CVE-2018-10653CriMay 23, 2018
    risk 0.67cvss 9.8epss 0.07

    There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10648CriMay 23, 2018
    risk 0.64cvss 9.8epss 0.01

    There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10654HigMay 23, 2018
    risk 0.53cvss 8.1epss 0.01

    There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10650HigMay 23, 2018
    risk 0.51cvss 7.8epss 0.01

    There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10652HigMay 23, 2018
    risk 0.49cvss 7.5epss 0.01

    There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

  • CVE-2017-9231HigJun 16, 2017
    risk 0.49cvss 7.5epss 0.02

    XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

  • CVE-2018-10651MedMay 23, 2018
    risk 0.40cvss 6.1epss 0.01

    There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10649MedMay 23, 2018
    risk 0.40cvss 6.1epss 0.01

    There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

  • CVE-2016-2789MedApr 7, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-6877MedMay 5, 2017
    risk 0.35cvss 5.3epss 0.01

    Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid…

  • CVE-2020-8209Aug 17, 2020
    risk 0.07cvss epss 0.49

    Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

  • CVE-2021-44520Apr 12, 2022
    risk 0.01cvss epss 0.06

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

  • CVE-2021-44519Apr 19, 2022
    risk 0.00cvss epss 0.03

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

  • CVE-2022-26151Apr 12, 2022
    risk 0.00cvss epss 0.08

    Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

  • CVE-2020-8253Sep 18, 2020
    risk 0.00cvss epss 0.02

    Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

  • CVE-2020-8212Aug 17, 2020
    risk 0.00cvss epss 0.02

    Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

  • CVE-2020-8211Aug 17, 2020
    risk 0.00cvss epss 0.02

    Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

  • CVE-2020-8210Aug 17, 2020
    risk 0.00cvss epss 0.02

    Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

  • CVE-2020-8208Aug 17, 2020
    risk 0.00cvss epss 0.01

    Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

  • CVE-2018-18571Jun 5, 2019
    risk 0.00cvss epss 0.03

    An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.