CVE-2009-2453: High severity tgstation 13 vulnerability
Published Jul 14, 2009
·Updated
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.
Affected Software
5 affected components
Citrix Presentation Server=4.5
Citrix Presentation Server=4.5
Citrix Presentation Server=4.5
Citrix Presentation Server=4.5-fp1
Citrix XenApp=4.5-fp3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 14, 2009
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2453?
CVE-2009-2453 is considered to have a medium severity due to the risk of unauthorized access.
2
How do I fix CVE-2009-2453?
To fix CVE-2009-2453, update your Citrix XenApp to the latest version or apply relevant patches and configurations.
3
What products are affected by CVE-2009-2453?
CVE-2009-2453 affects Citrix Presentation Server 4.5 and Citrix XenApp 4.5.
4
What type of vulnerability is CVE-2009-2453?
CVE-2009-2453 is an access control vulnerability that allows attackers to bypass intended restrictions.
5
Can CVE-2009-2453 be exploited remotely?
Yes, CVE-2009-2453 can potentially be exploited remotely due to the nature of the access policy issue.