CVE-2018-8889: Path Traversal
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8889?
CVE-2018-8889 is a directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier that could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
How severe is CVE-2018-8889?
CVE-2018-8889 has a severity rating of 4.7 (medium).
Which software versions are affected by CVE-2018-8889?
CVE-2018-8889 affects BlackBerry Enterprise Mobility Server (BEMS) versions up to and including 2.8.17.29.
How can an attacker exploit CVE-2018-8889?
An attacker can exploit CVE-2018-8889 by leveraging the directory traversal vulnerability in the Connect Service of BEMS to access arbitrary files.
Is there a fix available for CVE-2018-8889?
Yes, BlackBerry has released a fix for CVE-2018-8889. It is recommended to update to a patched version of the BlackBerry Enterprise Mobility Server.