CVE-2015-7997: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What are the cross-site scripting vulnerabilities in CVE-2015-7997?
CVE-2015-7997 describes multiple cross-site scripting (XSS) vulnerabilities found in the Nitro API of specific Citrix NetScaler products.
What versions of Citrix software are affected by CVE-2015-7997?
CVE-2015-7997 affects Citrix NetScaler Application Delivery Controller and Gateway versions prior to 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e.
How do I fix CVE-2015-7997?
To remediate CVE-2015-7997, users should upgrade to the latest versions of affected Citrix products as recommended in Citrix security advisories.
What impact does CVE-2015-7997 have on Citrix NetScaler users?
CVE-2015-7997 can allow attackers to execute malicious scripts on users' browsers, potentially compromising sensitive information.
Is CVE-2015-7997 a high-severity vulnerability?
CVE-2015-7997 is typically considered a high-severity vulnerability due to the potential for XSS attacks.