Stored Cross-Site Scripting Vulnerability in BlackBerry UEM Management Console
CVE-2018-8888

4.8MEDIUM

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
20 December 2018

What is CVE-2018-8888?

A stored cross-site scripting vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 enables attackers to embed script commands. These scripts can be executed later in the context of another Management Console administrator, potentially compromising sensitive data and system integrity.

Affected Version(s)

BlackBerry UEM 12.9.1 and earlier

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.