Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Storefront_server | Citrix | * | 2006 (excluding) |
Storefront_server | Citrix | 3.0 (including) | 3.0.8001 (excluding) |
Storefront_server | Citrix | 3.12 (including) | 3.12.5001 (excluding) |
Storefront_server | Citrix | 1912 (including) | 1912.0.1000 (excluding) |