CVE-2015-2682: Medium severity citrix command center vulnerability
Published Mar 26, 2015
·Updated
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.
Affected Software
2 affected components
Citrix Command Center=5.1
Citrix Command Center=5.2
Event History
Mar 26, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2682?
CVE-2015-2682 is rated as a high severity vulnerability due to the potential for credential exposure.
2
How do I fix CVE-2015-2682?
To fix CVE-2015-2682, upgrade Citrix Command Center to version 5.1 Build 35.4 or 5.2 Build 42.7 or later.
3
What type of attack does CVE-2015-2682 enable?
CVE-2015-2682 enables remote attackers to obtain sensitive credentials if the affected software versions are exposed.
4
Which versions of Citrix Command Center are affected by CVE-2015-2682?
CVE-2015-2682 affects Citrix Command Center versions prior to 5.1 Build 35.4 and 5.2 prior to Build 42.7.
5
Is CVE-2015-2682 a remote vulnerability?
Yes, CVE-2015-2682 is a remote vulnerability that allows unauthorized access to sensitive data.