First published: Fri Mar 03 2017(Updated: )
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flexera FlexNet Publisher | <=11.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5571 is classified as a medium severity vulnerability due to its potential for exploitation through open redirection.
To mitigate CVE-2017-5571, upgrade FlexNet Publisher to version 11.14.2 or later, which addresses this vulnerability.
CVE-2017-5571 affects Flexera FlexNet Publisher versions 11.14.1 and earlier, including its use in Citrix License Server.
Yes, CVE-2017-5571 can be exploited remotely, allowing attackers to redirect users to malicious websites.
CVE-2017-5571 can facilitate phishing attacks by redirecting users to arbitrary websites.