First published: Mon Aug 18 2014(Updated: )
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | =10.0 | |
BlackBerry Enterprise Server | =10.1.0 | |
BlackBerry Enterprise Server | =10.1.2 | |
BlackBerry Enterprise Server | =10.2.0 | |
BlackBerry Enterprise Server | =10.2.1 | |
BlackBerry Enterprise Server | <=5.0.4 | |
BlackBerry Enterprise Server | <=5.0.4 | |
BlackBerry Enterprise Server | <=5.0.4 | |
BlackBerry Enterprise Server Express | =5.0.4 | |
BlackBerry Enterprise Server Express | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1469 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
To remediate CVE-2014-1469, upgrade to BlackBerry Enterprise Server 5.0.4 MR7 or later, or to Enterprise Service versions 10.2.2 or higher.
CVE-2014-1469 exposes cleartext credentials during exception handling, allowing local users to read sensitive information.
CVE-2014-1469 affects BlackBerry Enterprise Server versions prior to 5.0.4 MR7 and Enterprise Service versions prior to 10.2.2.
No, CVE-2014-1469 requires local access to exploit the vulnerability by reading the exception log file.