Executive brief
A vulnerability in Citrix XenServer allows a user with restricted 'read-only' administrative access to cancel ongoing tasks initiated by other administrators. This could lead to operational disruptions or the intentional interruption of critical system maintenance and management activities. The issue affects the xapi component in versions up to and including 7.0.
Technical details
An authorization bypass vulnerability exists in the Linux Foundation xapi (Xen API) component of Citrix XenServer. The flaw allows an authenticated user with high-privilege but 'read-only' permissions to perform actions beyond their intended scope, specifically the cancellation of tasks managed by other administrative accounts. The vulnerability is reachable over the network and requires valid administrative credentials. Successful exploitation impacts the integrity of system operations by allowing unauthorized control over task lifecycles. Citrix has addressed this in security bulletin CTX220112.
Affected products
- Citrix XenServer through 7.0
Timeline
- 2017-01-30: disclosed
- 2017-01-30: advisory: NVD publication date