First published: Fri Dec 16 2016(Updated: )
A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Good Enterprise Mobility Server | <=2.2.22.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3129 is considered a critical vulnerability due to its potential for remote shell execution and local administrator rights acquisition.
To mitigate CVE-2016-3129, upgrade your BlackBerry Good Enterprise Mobility Server to a version later than 2.2.22.25.
CVE-2016-3129 affects BlackBerry Good Enterprise Mobility Server versions from 2.1.5.3 to 2.2.22.25.
Yes, CVE-2016-3129 can be exploited remotely, allowing attackers to execute commands on the affected server.
Exploitation of CVE-2016-3129 can lead to unauthorized access and control over the BlackBerry Good Enterprise Mobility Server, compromising sensitive data.