An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMobileiron Cloud
APPMobileiron≤ 10.6Mobileiron Core
APPMobileiron≤ 10.6Mobileiron Enterprise Connector
APPMobileiron≤ 10.6Mobileiron Reporting Database
APPMobileiron≤ 10.6Mobileiron Sentry
APPMobileiron≤ 10.6
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Powiązane podatności
CVE-2020-15505CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Zdalne wykonanie kodu (RCE) w MobileIron Core, Sentry i RDB
CVE-2020-15506CRITICAL9.8PL ✓ten sam produkt
Authentication bypass w MobileIron Core & Connector — pominięcie uwierzytelnienia
CVE-2013-7287CRITICAL9.8PL ✓ten sam produkt
Słaby schemat szyfrowania w MobileIron VSP i Sentry
CVE-2014-1409CRITICAL9.1PL ✓ten sam produkt
MobileIron VSP i Sentry — pominięcie uwierzytelnienia przez zaciemnione hasła w XML
CVE-2020-35138CRITICAL9.8PL ✓ten sam vendor
MobileIron Mobile@Work — zakodowany klucz szyfrowania poświadczeń