Vulnerabilities > Citrix > Xenmobile Server > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-19 CVE-2021-44519 Path Traversal vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
network
low complexity
citrix CWE-22
8.8
2022-04-13 CVE-2021-44520 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
network
low complexity
citrix CWE-77
8.8
2022-04-13 CVE-2022-26151 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
network
low complexity
citrix CWE-77
7.2
2020-09-18 CVE-2020-8253 Improper Authentication vulnerability in Citrix Xenmobile Server
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.
network
low complexity
citrix CWE-287
7.5
2020-08-17 CVE-2020-8210 Insufficiently Protected Credentials vulnerability in Citrix Xenmobile Server
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
network
low complexity
citrix CWE-522
7.5
2020-08-17 CVE-2020-8209 Path Traversal vulnerability in Citrix Xenmobile Server
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
network
low complexity
citrix CWE-22
7.5
2018-10-24 CVE-2018-18014 Improper Authentication vulnerability in Citrix Xenmobile Server
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001.
local
low complexity
citrix CWE-287
7.8
2018-10-24 CVE-2018-18013 Deserialization of Untrusted Data vulnerability in Citrix Xenmobile Server
* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input.
local
low complexity
citrix CWE-502
7.8
2018-05-23 CVE-2018-10654 Deserialization of Untrusted Data vulnerability in Citrix Xenmobile Server 10.7/10.8
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
network
high complexity
citrix CWE-502
8.1
2018-05-23 CVE-2018-10652 Information Exposure vulnerability in Citrix Xenmobile Server 10.7
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
network
low complexity
citrix CWE-200
7.5