SQL Injection Vulnerability in BlackBerry AtHoc Management Console
CVE-2023-21521

7.2HIGH

Key Information:

Vendor

Blackberry

Status
Vendor
CVE Published:
12 September 2023

What is CVE-2023-21521?

An SQL Injection vulnerability exists in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15. This flaw could enable an attacker to potentially access and manipulate sensitive database information, including reading and modifying data entries. Additionally, the vulnerability may allow the execution of administrative commands against the database, retrieval of files stored within the DBMS file system, and in certain instances, issuing commands directly to the underlying operating system.

Affected Version(s)

AtHoc 7.15

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.