High
Citrix XenMobile Server could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Citrix XenMobile Server could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Citrix XenMobile Server could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Citrix StoreFront Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input when configured to use SAML authentication. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Citrix SD-WAN could allow a remote authenticated attacker to gain unauthorized access to the system, caused by the use of hard-coded credentials. An attacker could exploit this vulnerability using the SD-WAN CLI to gain access to the shell.
Citrix SD-WAN is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Citrix
Please refer to the Citrix website for patches, updates, and workaround, visit: