Citrix Xenmobile Server vulnerabilities

22 known vulnerabilities affecting citrix/xenmobile_server.

Total CVEs
22
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH11MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2021-44519HIGHCVSS 8.8v10.13.0v10.14.02022-04-19
CVE-2021-44519 [HIGH] CWE-22 CVE-2021-44519: In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerab In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
nvd
CVE-2021-44520HIGHCVSS 8.8v10.13.0v10.14.02022-04-13
CVE-2021-44520 [HIGH] CWE-77 CVE-2021-44520: In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerabil In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
nvd
CVE-2022-26151HIGHCVSS 7.2v10.13.0v10.14.02022-04-13
CVE-2022-26151 [HIGH] CWE-77 CVE-2022-26151: Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
nvd
CVE-2020-8253HIGHCVSS 7.5≤ 10.8.0v10.9.0+3 more2020-09-18
CVE-2020-8253 [HIGH] CWE-287 CVE-2020-8253: Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 b Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.
nvd
CVE-2020-8211CRITICALCVSS 9.8≤ 10.8.0v10.9.0+3 more2020-08-17
CVE-2020-8211 [CRITICAL] CWE-77 CVE-2020-8211: Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
nvd
CVE-2020-8212CRITICALCVSS 9.8≤ 10.9.0v10.10.0+2 more2020-08-17
CVE-2020-8212 [CRITICAL] CWE-749 CVE-2020-8212: Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 b Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.
nvd
CVE-2020-8210HIGHCVSS 7.5≤ 10.8.0v10.9.0+3 more2020-08-17
CVE-2020-8210 [HIGH] CWE-200 CVE-2020-8210: Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Ser Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
nvd
CVE-2020-8209HIGHCVSS 7.5ExploitedPoC≤ 10.8.0v10.9.0+3 more2020-08-17
CVE-2020-8209 [HIGH] CWE-22 CVE-2020-8209: Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 b Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
nvd
CVE-2020-8208MEDIUMCVSS 6.1≤ 10.8.0v10.9.0+3 more2020-08-17
CVE-2020-8208 [MEDIUM] CWE-79 CVE-2020-8208: Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).
nvd
CVE-2018-18571CRITICALCVSS 9.1v10.8.0v10.9.02019-06-05
CVE-2018-18571 [CRITICAL] CWE-287 CVE-2018-18571: An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 befo An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
nvd
CVE-2018-18013HIGHCVSS 7.8≤ 10.8.02018-10-24
CVE-2018-18013 [HIGH] CWE-502 CVE-2018-18013: * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accep * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability,
nvd
CVE-2018-18014MEDIUMCVSS 4.8≤ 10.8.02018-10-24
CVE-2018-18014 [MEDIUM] CWE-287 CVE-2018-18014: * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to exec * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to config
nvd
CVE-2018-10653CRITICALCVSS 9.8PoCv10.8v10.72018-05-23
CVE-2018-10653 [CRITICAL] CWE-611 CVE-2018-10653: There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 befor There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
nvd
CVE-2018-10648CRITICALCVSS 9.8v10.8v10.72018-05-23
CVE-2018-10648 [CRITICAL] CWE-434 CVE-2018-10648: There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
nvd
CVE-2018-10650HIGHCVSS 7.8v10.8v10.72018-05-23
CVE-2018-10650 [HIGH] CWE-426 CVE-2018-10650: There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 an There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
nvd
CVE-2018-10652HIGHCVSS 7.5v10.72018-05-23
CVE-2018-10652 [HIGH] CWE-200 CVE-2018-10652: There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
nvd
CVE-2018-10654HIGHCVSS 8.1v10.8v10.72018-05-23
CVE-2018-10654 [HIGH] CWE-502 CVE-2018-10654: There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 befo There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
nvd
CVE-2018-10651MEDIUMCVSS 6.1v10.8v10.72018-05-23
CVE-2018-10651 [MEDIUM] CWE-601 CVE-2018-10651: There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before R There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
nvd
CVE-2018-10649MEDIUMCVSS 6.1v10.72018-05-23
CVE-2018-10649 [MEDIUM] CWE-79 CVE-2018-10649: There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
nvd
CVE-2017-9231HIGHCVSS 7.5v9.0v10.0+6 more2017-06-16
CVE-2017-9231 [HIGH] CWE-611 CVE-2017-9231: XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allo XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.
nvd