CVE-2016-6877: Input Validation
DISPUTED Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid vulnerability" because an exploitation scenario would involve a man-in-the-middle attack against a TLS session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6877?
CVE-2016-6877 is considered a disputed vulnerability by the vendor, indicating it may not have significant impact.
How do I fix CVE-2016-6877?
To mitigate the potential risks associated with CVE-2016-6877, ensure you upgrade Citrix XenMobile Server to version 10.5.0.24 or later.
Which versions of Citrix XenMobile Server are affected by CVE-2016-6877?
CVE-2016-6877 affects Citrix XenMobile Server versions up to and including 10.3.6.310.
Can CVE-2016-6877 be exploited remotely?
CVE-2016-6877 can potentially be exploited remotely by man-in-the-middle attackers leveraging HTTP Host header vulnerabilities.
What types of attacks are related to CVE-2016-6877?
CVE-2016-6877 relates to HTTP redirection attacks that can occur through manipulated HTTP requests.