XML External Entity Injection in BlackBerry AtHoc Management System
CVE-2019-8997
5.9MEDIUM
What is CVE-2019-8997?
The vulnerability in the Management System of BlackBerry AtHoc allows attackers to exploit an XML External Entity Injection flaw. By injecting malicious XML into an existing field, attackers may gain unauthorized access to local files on the application server and could leverage this access to initiate unexpected network requests, potentially compromising sensitive data.
Affected Version(s)
BlackBerry AtHoc 7.6 and earlier
