CVE-2016-1914
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.10% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- blackberry/blackberry enterprise service
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2016/Feb/95Mailing List, Third Party Advisory, VDB Entry
- http://security-assessment.com/files/documents/advisory/Blackberry%20BES12%20Self-Service%20Multiple%20Vulnerabilities.pdfExploit, Third Party Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000038033Patch, Vendor Advisory
- http://www.securitytracker.com/id/1035095
- https://www.exploit-db.com/exploits/39481/
- http://seclists.org/fulldisclosure/2016/Feb/95Mailing List, Third Party Advisory, VDB Entry
- http://security-assessment.com/files/documents/advisory/Blackberry%20BES12%20Self-Service%20Multiple%20Vulnerabilities.pdfExploit, Third Party Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000038033Patch, Vendor Advisory
- http://www.securitytracker.com/id/1035095
- https://www.exploit-db.com/exploits/39481/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.