An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
2019-06-05T15:29:00.590
2024-11-21T03:56:10.983
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.8.0 | Yes |
Application | citrix | xenmobile_server | 10.9.0 | Yes |
Application | citrix | xenmobile_server | 10.9.0 | Yes |
Application | citrix | xenmobile_server | 10.9.0 | Yes |