CVE-2019-8999: XEE
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2019-8999?
CVE-2019-8999 is an XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a.
How does the CVE-2019-8999 vulnerability work?
The CVE-2019-8999 vulnerability allows an attacker to potentially gain read access to files on any system reachable by the UEM service account by exploiting an XML External Entity vulnerability in the UEM Core of BlackBerry UEM.
What is the severity of CVE-2019-8999?
CVE-2019-8999 has a severity rating of high, with a severity value of 7.5.
Which versions of BlackBerry UEM are affected by CVE-2019-8999?
BlackBerry UEM version(s) earlier than 12.10.1a are affected by CVE-2019-8999.
How can I fix the CVE-2019-8999 vulnerability?
To fix the CVE-2019-8999 vulnerability, update BlackBerry UEM to version 12.10.1a or later.