Information Disclosure Vulnerability in BlackBerry QNX Software Development Platform
CVE-2019-8998

7.8HIGH

What is CVE-2019-8998?

An information disclosure vulnerability exists in the procfs service of the BlackBerry QNX Software Development Platform. This flaw allows attackers to potentially gain unauthorized access to the address space of specific processes. Targeting versions 6.5.0 SP1 and earlier, this vulnerability highlights a risk where sensitive information may be exposed, posing challenges for application security and data integrity.

Affected Version(s)

BlackBerry QNX Software Development Platform (QNX SDP) 6.5.0 SP1 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.