Analyst readout for executives and security teams
Plain-English summary
CVE-2002-0504 is a cross-site scripting issue in Citrix NFuse 1.6 and earlier. A remote attacker could cause script to run in another user's browser through affected launch pages. The business risk depends on whether this very old NFuse software is still exposed internally or externally.
Executive priority
Treat this as a legacy exposure cleanup item. It becomes more urgent if NFuse launch pages are internet-facing or used by privileged Citrix users, but the bundle does not support claims of active exploitation.
Technical view
The issue is improper quoting of getLastError output when handling the NFuse_Application parameter in launch.jsp and launch.asp. Sources identify Citrix NFuse 1.6 and earlier as affected. No CVSS score, CWE mapping, official fix detail, or current exploitation evidence is provided in the bundle.
Likely exposure
Exposure is likely limited to organizations still running legacy Citrix NFuse 1.6 or earlier, especially where launch.jsp or launch.asp is reachable by users or the internet.
Exploitation context
The sources describe remote cross-site scripting but do not show CISA KEV listing or cited evidence of active exploitation. Successful abuse would rely on getting a user to interact with affected NFuse launch functionality.
Researcher notes
Evidence is sparse and old. The useful validation focus is version confirmation, route reachability, and whether getLastError output is rendered without proper quoting around NFuse_Application handling. Avoid assuming modern Citrix products are affected without separate evidence.
Mitigation direction
- Identify and retire any Citrix NFuse 1.6 or earlier deployments.
- Check Citrix or legacy product guidance for supported upgrade or replacement paths.
- Restrict access to affected NFuse launch pages while remediation is planned.
- Apply compensating web filtering for script injection patterns if legacy removal is delayed.
Validation and detection
- Inventory web servers for Citrix NFuse components and affected launch pages.
- Confirm whether launch.jsp or launch.asp is reachable by untrusted users.
- Review application logs for suspicious NFuse_Application parameter activity.
- Verify the deployed NFuse version is newer than 1.6 or replaced.
Public sources used
Based on public source material and reviewed before publication.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2002-0504 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- nfuse-launch-css(8659)CVE reference · vdb-entry, x_refsource_XF
- 20020327 NFuse Cross Site Scripting vulnerabilityCVE reference · mailing-list, x_refsource_BUGTRAQ
- 4372CVE reference · vdb-entry, x_refsource_BID
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
