PT-2017-9041 · Citrix · Citrix Xenmobile Server

CVE-2016-6877

·

Publicado

2017-05-05

·

Atualizado

2024-08-06

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Citrix XenMobile Server versions prior to 10.5.0.24
Description The issue allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. However, the vendor reports that their internal analysis concluded this was not a valid vulnerability because an exploitation scenario would involve a man-in-the-middle attack against a TLS session.
Recommendations For versions prior to 10.5.0.24, update to version 10.5.0.24 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6877

Produtos afetados

Citrix Xenmobile Server