CVE-2017-3894
A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator…
Does this matter?
Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.
Description
A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target administrator to view the specific location of the malicious script within the Management Console.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- blackberry/enterprise service · blackberry/unified endpoint manager
- Source
- secure@blackberry.com
References
- http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000044565Vendor Advisory
- http://www.securityfocus.com/bid/98552
- http://www.securitytracker.com/id/1038465
- http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000044565Vendor Advisory
- http://www.securityfocus.com/bid/98552
- http://www.securitytracker.com/id/1038465
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.