An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMobileiron Cloud
APPMobileiron≤ 10.6Mobileiron Core
APPMobileiron≤ 10.6Mobileiron Enterprise Connector
APPMobileiron≤ 10.6Mobileiron Reporting Database
APPMobileiron≤ 10.6Mobileiron Sentry
APPMobileiron≤ 10.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2020-15505CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w MobileIron Core, Sentry i RDB
CVE-2020-15506CRITICAL9.8PL ✓same product
Authentication bypass w MobileIron Core & Connector — pominięcie uwierzytelnienia
CVE-2013-7287CRITICAL9.8PL ✓same product
Słaby schemat szyfrowania w MobileIron VSP i Sentry
CVE-2014-1409CRITICAL9.1PL ✓same product
MobileIron VSP i Sentry — pominięcie uwierzytelnienia przez zaciemnione hasła w XML
CVE-2020-35138CRITICAL9.8PL ✓same vendor
MobileIron Mobile@Work — zakodowany klucz szyfrowania poświadczeń