7.5
CVE-2019-13608
- EPSS 28.88%
- Veröffentlicht 29.08.2019 19:15:13
- Zuletzt bearbeitet 06.11.2025 16:02:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Storefront Server Version >= 1811 < 1903
Citrix ≫ Storefront Server Version < 3.12.4000
Citrix ≫ Storefront Server Version < 3.0.8000
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
SchwachstelleCitrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 28.88% | 0.964 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.