Authentication Bypass in BlackBerry Workspaces Server under Appliance-X
CVE-2021-22155

8.8HIGH

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
13 May 2021

What is CVE-2021-22155?

An Authentication Bypass flaw exists in the SAML Authentication component of BlackBerry Workspaces Server when deployed with Appliance-X. This vulnerability allows unauthorized actors to exploit the system, potentially gaining access to the application with the privileges of a targeted user. The affected versions include 10.1, 9.1, and earlier iterations, highlighting the importance of immediate action to mitigate risks associated with this security issue.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.