|
Citrix Nfuse Published Applications Information Leak Vulnerability
Citrix Nfuse is an application portal server meant to provide the functionality of any application on the server via a web browser. Nfuse works in conjunction with a previously-installed webserver. If a request for 'applist.asp' is submitted without authentication, Nfuse reportedly will disclose a list of all published applications. There have been reports that this issue could not be reproduced. * The result of this issue is likely due to a session cookie which is not deleted until all browser sessions are shut down. If the user properly logs out, the session cookie is modified such that they must re-authenticate. |
|
|
Privacy Statement |