CVE-2020-8209
Summary
| CVE | CVE-2020-8209 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-17 16:15:00 UTC |
| Updated | 2020-08-20 15:41:00 UTC |
| Description | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Xenmobile Server | 10.10.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch5 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | 10.10.0 | rolling_patch5 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.11.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.12.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | - | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch1 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch2 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch3 | All | All |
| Application | Citrix | Xenmobile Server | 10.9.0 | rolling_patch4 | All | All |
| Application | Citrix | Xenmobile Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix Endpoint Management (CEM) Security Update | MISC | support.citrix.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.