CVE-2009-2453

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:citrix:presentation_server:4.5:-:se:*:*:*:*:*
cpe:2.3:a:citrix:presentation_server:4.5:-:windows_server_2003:*:*:*:*:*
cpe:2.3:a:citrix:presentation_server:4.5:-:windows_server_2003_x64:*:*:*:*:*
cpe:2.3:a:citrix:presentation_server:4.5:fp1:*:*:*:*:*:*
cpe:2.3:a:citrix:xenapp:4.5:fp3:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://osvdb.org/53900 - () http://osvdb.org/53900 -
References () http://secunia.com/advisories/34865 - Vendor Advisory () http://secunia.com/advisories/34865 - Vendor Advisory
References () http://support.citrix.com/article/CTX118792 - Patch, Vendor Advisory () http://support.citrix.com/article/CTX118792 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/34691 - Patch () http://www.securityfocus.com/bid/34691 - Patch
References () http://www.securitytracker.com/id?1022114 - Patch () http://www.securitytracker.com/id?1022114 - Patch
References () http://www.vupen.com/english/advisories/2009/1154 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/1154 - Patch, Vendor Advisory

Information

Published : 2009-07-14 14:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2453

Mitre link : CVE-2009-2453

CVE.ORG link : CVE-2009-2453


JSON object : View

Products Affected

citrix

  • presentation_server
  • xenapp
CWE
CWE-264

Permissions, Privileges, and Access Controls