SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-3129

A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the…

MEDIUM 6.6EPSS 2.90%

Does this matter?

Lower severity and a low EPSS score (2.90%). Track it; it rarely justifies an emergency change on its own.

Description

A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.

CVSS 3.0
6.6 MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.90% probability · 86th percentile
CISA KEV
Not listed
Affected
blackberry/good enterprise mobility server
Source
secure@blackberry.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.