SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-8888

A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console…

MEDIUM 4.8EPSS 0.51%

Does this matter?

Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.

Description

A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.

CVSS 3.0
4.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.51% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
blackberry/unified endpoint manager
Source
secure@blackberry.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.