First published: Tue Sep 18 2018(Updated: )
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Mobility Server | <=2.8.17.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8889 is a directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier that could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
CVE-2018-8889 has a severity rating of 4.7 (medium).
CVE-2018-8889 affects BlackBerry Enterprise Mobility Server (BEMS) versions up to and including 2.8.17.29.
An attacker can exploit CVE-2018-8889 by leveraging the directory traversal vulnerability in the Connect Service of BEMS to access arbitrary files.
Yes, BlackBerry has released a fix for CVE-2018-8889. It is recommended to update to a patched version of the BlackBerry Enterprise Mobility Server.