CVE-2018-10654
https://notcve.org/view.php?id=CVE-2018-10654
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. Hay una vulnerabilidad de deserialización Java de la biblioteca Hazelcast en Citrix XenMobile Server, en versiones 10.8 anteriores a la RP2 y 10.7 anteriores a la RP3. • https://support.citrix.com/article/CTX234879 • CWE-502: Deserialization of Untrusted Data •
CVE-2018-10648
https://notcve.org/view.php?id=CVE-2018-10648
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. Hay vulnerabilidades de subida de archivos sin autenticar en Citrix XenMobile Server, en versiones 10.8 anteriores a la RP2 y 10.7 anteriores a la RP3. • https://support.citrix.com/article/CTX234879 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-10652
https://notcve.org/view.php?id=CVE-2018-10652
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. Hay una vulnerabilidad de fuga de información sensible en Citrix XenMobile Server, en versiones 10.7 anteriores a la RP3. • https://support.citrix.com/article/CTX234879 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-10653 – Citrix XenMobile Server 10.8 - XML External Entity Injection
https://notcve.org/view.php?id=CVE-2018-10653
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. Hay una vulnerabilidad de procesamiento de XEE (XML External Entity) en Citrix XenMobile Server, en versiones 10.8 anteriores a la RP2 y 10.7 anteriores a la RP3. Citrix XenMobile Server version 10.8 suffers from an XML external entity injection vulnerability. • https://www.exploit-db.com/exploits/47951 http://packetstormsecurity.com/files/156037/Citrix-XenMobile-Server-10.8-XML-Injection.html https://support.citrix.com/article/CTX234879 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2018-10649
https://notcve.org/view.php?id=CVE-2018-10649
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. Hay una vulnerabilidad de Cross-Site Scripting (XSS) en Citrix XenMobile Server, en versiones 10.7 anteriores a la RP3. • https://support.citrix.com/article/CTX234879 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •