CVE-2014-1469: Medium severity blackberry enterprise server vulnerability
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1469?
CVE-2014-1469 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2014-1469?
To remediate CVE-2014-1469, upgrade to BlackBerry Enterprise Server 5.0.4 MR7 or later, or to Enterprise Service versions 10.2.2 or higher.
What types of credentials are exposed in CVE-2014-1469?
CVE-2014-1469 exposes cleartext credentials during exception handling, allowing local users to read sensitive information.
Which versions of BlackBerry software are affected by CVE-2014-1469?
CVE-2014-1469 affects BlackBerry Enterprise Server versions prior to 5.0.4 MR7 and Enterprise Service versions prior to 10.2.2.
Can this issue be exploited remotely in CVE-2014-1469?
No, CVE-2014-1469 requires local access to exploit the vulnerability by reading the exception log file.