First published: Wed Feb 17 2016(Updated: )
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler Application Delivery Controller | ||
Citrix NetScaler | =10.1 | |
Citrix NetScaler | =10.5 | |
Citrix NetScaler | =10.5e | |
Citrix NetScaler | =11.0 | |
Citrix NetScaler Gateway |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2072 is classified as a medium-security vulnerability due to its potential for clickjacking attacks.
To remediate CVE-2016-2072, update to Citrix NetScaler Application Delivery Controller and NetScaler Gateway versions at or above the required builds which mitigate this vulnerability.
CVE-2016-2072 affects Citrix NetScaler Application Delivery Controller versions 10.1, 10.5, and 11.0 prior to specified builds.
CVE-2016-2072 enables remote attackers to perform clickjacking attacks, potentially compromising user interactions.
No, exploitation of CVE-2016-2072 can occur without direct user interaction, making it particularly concerning.