CVE-2015-7997
Summary
| CVE | CVE-2015-7997 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-17 15:59:19 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Citrix | Netscaler Application Delivery Controller Firmware | 10.1 | All | All | All |
| Operating System | Citrix | Netscaler Application Delivery Controller Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 10.1 | All | All | All |
| Operating System | Citrix | Netscaler Gateway Firmware | 10.5 | All | All | All |
| Operating System | Citrix | Netscaler Service Delivery Appliance Service Vm | 10.5e | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix NetScaler Service Delivery Appliance and Citrix CloudBridge WAN Optimization Appliance Multiple Security Updates | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch, Vendor Advisory |
| Citrix NetScaler Service Delivery Appliance Bugs Let Local Users Obtain Potentially Sensitive Information and Remote Users Conduct Cross-Site Scripting Attack and Obtain Passwords - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.