CVE-2019-7217
published 2019-05-13CVE-2019-7217: Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.00%
78.4th percentile
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | sharefile | < 19.12 | 19.12 |
| citrix | sharefile | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jg7x-2whq-4cvh: Citrix ShareFile through 19
ghsa_unreviewed·2022-05-24
CVE-2019-7217 [HIGH] GHSA-jg7x-2whq-4cvh: Citrix ShareFile through 19
Citrix ShareFile through 19.1 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
Citrix
CVE-2019-7217: Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the
vendor_citrix·2019-05-13·CVSS 7.5
CVE-2019-7217 [HIGH] CWE-203 CVE-2019-7217: Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the
CVE-2019-7217: Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-13
Published