Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3894


A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target administrator to view the specific location of the malicious script within the Management Console.


Published

2017-05-10T16:29:00.150

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application blackberry enterprise_service 12.0 Yes
Application blackberry enterprise_service 12.0.1 Yes
Application blackberry enterprise_service 12.1 Yes
Application blackberry enterprise_service 12.1.0 Yes
Application blackberry enterprise_service 12.1.1 Yes
Application blackberry enterprise_service 12.2.0 Yes
Application blackberry enterprise_service 12.2.1 Yes
Application blackberry enterprise_service 12.3.0 Yes
Application blackberry enterprise_service 12.3.1 Yes
Application blackberry enterprise_service 12.4.0 Yes
Application blackberry enterprise_service 12.4.1 Yes
Application blackberry enterprise_service 12.5.0 Yes
Application blackberry enterprise_service 12.5.1 Yes
Application blackberry enterprise_service 12.5.2 Yes
Application blackberry unified_endpoint_manager ≤ 12.6.1 Yes

References