HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2020-15507

CVSS 7.5v3.1pub. 2020-07-07upd. 2024-11-21

An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Mobileiron Cloud

    APP
    Mobileiron
    ≤ 10.6
  • Mobileiron Core

    APP
    Mobileiron
    ≤ 10.6
  • Mobileiron Enterprise Connector

    APP
    Mobileiron
    ≤ 10.6
  • Mobileiron Reporting Database

    APP
    Mobileiron
    ≤ 10.6
  • Mobileiron Sentry

    APP
    Mobileiron
    ≤ 10.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2020-15505CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu (RCE) w MobileIron Core, Sentry i RDB

CVE-2020-15506CRITICAL9.8PL ✓same product

Authentication bypass w MobileIron Core & Connector — pominięcie uwierzytelnienia

CVE-2013-7287CRITICAL9.8PL ✓same product

Słaby schemat szyfrowania w MobileIron VSP i Sentry

CVE-2014-1409CRITICAL9.1PL ✓same product

MobileIron VSP i Sentry — pominięcie uwierzytelnienia przez zaciemnione hasła w XML

CVE-2020-35138CRITICAL9.8PL ✓same vendor

MobileIron Mobile@Work — zakodowany klucz szyfrowania poświadczeń