Home/Product/citrix xenmobile server
Product

citrix xenmobile server

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-44519
all versions
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code
8.8HIGH
CVE-2022-26151
all versions
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
7.2HIGH
CVE-2021-44520
all versions
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code ex
8.8HIGH
CVE-2020-8253
<= 10.8.0
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Se
7.5HIGH
CVE-2020-8212
<= 10.9.0
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Se
9.8CRITICAL
CVE-2020-8211
<= 10.8.0
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile
9.8CRITICAL
CVE-2020-8210
<= 10.8.0
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix X
7.5HIGH
CVE-2020-8209
<= 10.8.0
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Se
7.5HIGH
CVE-2020-8208
<= 10.8.0
Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile
6.1MEDIUM
CVE-2018-18571
all versions
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0
9.1CRITICAL
CVE-2018-18014
<= 10.8.0
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by
4.8MEDIUM
CVE-2018-18013
<= 10.8.0
* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If t
7.8HIGH
CVE-2018-10654
all versions
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
8.1HIGH
CVE-2018-10653
all versions
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
9.8CRITICAL
CVE-2018-10652
all versions
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
7.5HIGH
CVE-2018-10651
all versions
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
6.1MEDIUM
CVE-2018-10650
all versions
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
7.8HIGH
CVE-2018-10649
all versions
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
6.1MEDIUM
CVE-2018-10648
all versions
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
9.8CRITICAL
CVE-2017-9231
all versions
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensiti
7.5HIGH
CVE-2016-6877
<= 10.3.6.310
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving
5.3MEDIUM
CVE-2016-2789
all versions
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, a
6.1MEDIUM
threatengine.sh