Reflected Cross-Site Scripting in BlackBerry UEM Management Console
CVE-2017-17442

6.1MEDIUM

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
13 March 2018

What is CVE-2017-17442?

In the BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability exists that can be exploited by an attacker. By crafting a specially designed malicious link, an attacker can trick users with legitimate access into clicking the link. This can lead to the execution of unauthorized script commands within the context of the user's affected Management Console account, potentially compromising sensitive data and functionality.

Affected Version(s)

UEM Management Console 12.7.1 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.