CVE-2020-8209: Path Traversal
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8209?
CVE-2020-8209 is a vulnerability that involves improper access control in Citrix XenMobile Server, allowing an attacker to read arbitrary files.
Which versions of Citrix XenMobile Server are affected by CVE-2020-8209?
CVE-2020-8209 affects Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6, and Citrix XenMobile Server before 10.9 RP5.
What is the severity of CVE-2020-8209?
CVE-2020-8209 has a severity rating of 7.5 (High).
How can an attacker exploit CVE-2020-8209?
An attacker can exploit CVE-2020-8209 by leveraging improper access control to read arbitrary files.
Is there a fix for CVE-2020-8209?
Yes, Citrix has released a fix for CVE-2020-8209. Refer to the official Citrix support article for more information.