CVE-2017-9231XML External Entity (XXE) Injection in Citrix Xenmobile Server

Severity
7.5HIGHNVD
EPSS
0.4%
top 39.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateMay 17

Description

XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

🔴Vulnerability Details

1
GHSA
GHSA-f7rq-9qg8-cchw: XML external entity (XXE) vulnerability in Citrix XenMobile Server 92022-05-17

📋Vendor Advisories

2
Citrix
CVE-2017-9231: XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via u2017-06-16
Citrix
Citrix Security Bulletin CTX220138