CVE-2018-8888: XSS
Published Dec 20, 2018
·Updated
A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
Affected Software
1 affected component
BlackBerry Unified Endpoint Manager<12.10.0
Event History
Dec 20, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-8888?
CVE-2018-8888 is a stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0.
2
How does CVE-2018-8888 affect BlackBerry UEM?
CVE-2018-8888 allows an attacker to store script commands that could later be executed in the context of another Management Console administrator.
3
Which version of BlackBerry UEM is affected by CVE-2018-8888?
BlackBerry UEM versions earlier than 12.10.0 are affected by CVE-2018-8888.
4
What is the severity of CVE-2018-8888?
CVE-2018-8888 has a severity rating of medium (4.8).
5
How can I fix CVE-2018-8888?
To fix CVE-2018-8888, update BlackBerry UEM to version 12.10.0 or later.