PT-2017-9041 · Citrix · Citrix Xenmobile Server
CVE-2016-6877
·
Publicado
2017-05-05
·
Atualizado
2024-08-06
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Citrix XenMobile Server versions prior to 10.5.0.24
Description
The issue allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the
HTTP Host header and a cached page. However, the vendor reports that their internal analysis concluded this was not a valid vulnerability because an exploitation scenario would involve a man-in-the-middle attack against a TLS session.Recommendations
For versions prior to 10.5.0.24, update to version 10.5.0.24 or later to resolve the issue.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Xenmobile Server