First published: Thu Apr 14 2016(Updated: )
Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Command Center | =5.1 | |
Citrix Command Center | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7999 has a high severity level due to its potential for allowing remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2015-7999, upgrade to Citrix Command Center version 5.1 Build 36.7 or newer, or version 5.2 Build 44.11 or newer.
CVE-2015-7999 exhibits multiple SQL injection vulnerabilities specifically within the Administration Web UI servlets.
Remote authenticated users of Citrix Command Center versions prior to the specified builds are affected by CVE-2015-7999.
Attackers can potentially execute arbitrary SQL commands on vulnerable systems due to the SQL injection vulnerabilities in CVE-2015-7999.