Xenmobile Server
CVEs (22)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10653 | Cri | 0.67 | 9.8 | 0.07 | May 23, 2018 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | ||
| CVE-2020-8212 | Cri | 0.64 | 9.8 | 0.02 | Aug 17, 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality. | ||
| CVE-2020-8211 | Cri | 0.64 | 9.8 | 0.02 | Aug 17, 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection. | ||
| CVE-2018-10648 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2018 | There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | ||
| CVE-2018-18571 | Cri | 0.59 | 9.1 | 0.03 | Jun 5, 2019 | An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device. | ||
| CVE-2021-44520 | Hig | 0.58 | 8.8 | 0.06 | Apr 13, 2022 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges. | ||
| CVE-2021-44519 | Hig | 0.57 | 8.8 | 0.03 | Apr 19, 2022 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution. | ||
| CVE-2020-8209 | Hig | 0.53 | 7.5 | 0.49 | Aug 17, 2020 | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files. | ||
| CVE-2018-10654 | Hig | 0.53 | 8.1 | 0.01 | May 23, 2018 | There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | ||
| CVE-2018-18013 | Hig | 0.51 | 7.8 | 0.03 | Oct 24, 2018 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code… | ||
| CVE-2018-10650 | Hig | 0.51 | 7.8 | 0.01 | May 23, 2018 | There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | ||
| CVE-2020-8253 | Hig | 0.49 | 7.5 | 0.02 | Sep 18, 2020 | Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files. | ||
| CVE-2020-8210 | Hig | 0.49 | 7.5 | 0.02 | Aug 17, 2020 | Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account. | ||
| CVE-2018-10652 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2018 | There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. | ||
| CVE-2017-9231 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2017 | XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors. | ||
| CVE-2022-26151 | Hig | 0.47 | 7.2 | 0.08 | Apr 13, 2022 | Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. | ||
| CVE-2020-8208 | Med | 0.40 | 6.1 | 0.01 | Aug 17, 2020 | Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS). | ||
| CVE-2018-10651 | Med | 0.40 | 6.1 | 0.01 | May 23, 2018 | There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | ||
| CVE-2018-10649 | Med | 0.40 | 6.1 | 0.01 | May 23, 2018 | There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. | ||
| CVE-2016-2789 | Med | 0.40 | 6.1 | 0.01 | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
- risk 0.67cvss 9.8epss 0.07
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- risk 0.64cvss 9.8epss 0.02
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.
- risk 0.64cvss 9.8epss 0.02
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- risk 0.59cvss 9.1epss 0.03
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
- risk 0.58cvss 8.8epss 0.06
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
- risk 0.57cvss 8.8epss 0.03
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
- risk 0.53cvss 7.5epss 0.49
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
- risk 0.53cvss 8.1epss 0.01
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- risk 0.51cvss 7.8epss 0.03
* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code…
- risk 0.51cvss 7.8epss 0.01
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- risk 0.49cvss 7.5epss 0.02
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.
- risk 0.49cvss 7.5epss 0.02
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
- risk 0.49cvss 7.5epss 0.01
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
- risk 0.49cvss 7.5epss 0.02
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.
- risk 0.47cvss 7.2epss 0.08
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
- risk 0.40cvss 6.1epss 0.01
Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- risk 0.40cvss 6.1epss 0.01
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Page 1 of 2