RULE(RULE ID:332470)

Rule General Information
Release Date: 2020-11-19
Rule Name: Citrix XenMobile Server Directory Traversal Vulnerability (CVE-2020-8209)
Severity:
CVE ID:
Rule Protection Details
Description: Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux
Reference: https://support.citrix.com/article/CTX277457
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.citrix.com/article/CTX277457