Pages

Thursday, February 16, 2012

CTX132219 - Multiple Vulnerabilities in Citrix XenServer Web Self Service - #Citrix Knowledge Center

CTX132219 - Multiple Vulnerabilities in Citrix XenServer Web Self Service - Citrix Knowledge Center:

'via Blog this'

Multiple Vulnerabilities in Citrix XenServer Web Self Service

Document ID: CTX132219 / Created On: Feb 15, 2012 / Updated On: Feb 15, 2012
Average Rating: not yet rated

Severity: Medium

Description of Problem

A number of security vulnerabilities have been identified in the management web interface of Citrix XenServer Web Self Service. These vulnerabilities affect all currently supported versions of Web Self Service prior to version 1.1.1.

Mitigating Factors

Customers who have installed XenServer but have not additionally downloaded and installed the optional Web Self Service component are not affected by these vulnerabilities.

What Customers Should Do

These vulnerabilities have been addressed in a new version of the Web Self Service virtual appliance. Citrix recommends that customers using Web Self Service upgrade their virtual appliance to version 1.1.1.

The new version of the Web Self Service virtual appliance can be obtained from the following location:

http://www.citrix.com/English/ss/downloads/details.asp?downloadId=2313062&productId=683148

Acknowledgements

Citrix thanks Maxin Tsoy, Kirill Mosolov and Ilya Smith of Positive Research Center (http://www.ptsecurity.com/) for working with us to protect Citrix customers.

What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at http://www.citrix.com/site/ss/supportContacts.asp.

Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. If you would like to report a security issue to Citrix, please compose an e-mail to secure@citrix.com stating the exact version of the product in which the vulnerability was found and the steps needed to reproduce the vulnerability.


No comments:

Post a Comment