CVE-2018-10654: High severity citrix xenmobile vulnerability
Published May 23, 2018
·Updated
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Affected Software
5 affected components
Citrix XenMobile Server=10.8
Citrix XenMobile Server=10.8-rp1
Citrix XenMobile Server=10.7
Citrix XenMobile Server=10.7-rp1
Citrix XenMobile Server=10.7-rp2
Event History
May 23, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10654?
CVE-2018-10654 has been assigned a severity rating of medium due to its potential for exploitation via Java deserialization vulnerabilities.
2
How do I fix CVE-2018-10654?
To fix CVE-2018-10654, upgrade Citrix XenMobile Server to version 10.8 RP2 or 10.7 RP3 or later.
3
Which versions of Citrix XenMobile are affected by CVE-2018-10654?
CVE-2018-10654 affects Citrix XenMobile Server versions 10.7 and 10.8 prior to the respective release patches RP2 and RP3.
4
What type of vulnerability is CVE-2018-10654?
CVE-2018-10654 is classified as a Java Deserialization Vulnerability affecting the Hazelcast Library.
5
Is there a workaround for CVE-2018-10654?
There are no official workarounds for CVE-2018-10654; the recommended action is to upgrade to a patched version.