HIGH · 7.5

CVE-2009-2453

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to byp...

Vulnerability Description

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CitrixPresentation Server4.5
CitrixXenapp4.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2453?

CVE-2009-2453 is a vulnerability with a CVSS score of 7.5 (HIGH). Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to byp...

How severe is CVE-2009-2453?

CVE-2009-2453 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2453?

Check the references section above for vendor advisories and patch information. Affected products include: Citrix Presentation Server, Citrix Xenapp.