CVE-2021-22154: Medium severity blackberry unified endpoint management vulnerability
Published May 13, 2021
·Updated
An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially gain access to a victim's web history.
Affected Software
11 affected components
Blackberry Unified Endpoint Management<=12.12.0
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_1
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_2
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_3
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_4
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_5
Blackberry Unified Endpoint Management=12.12.1a-quick_fix_6
Blackberry Unified Endpoint Management=12.13.0
Blackberry Unified Endpoint Management=12.13.0-mr1
Blackberry Unified Endpoint Management=12.13.1-quick_fix_1
Blackberry Unified Endpoint Management=12.13.1-quick_fix_2
Event History
May 13, 2021
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
Description
Frequently Asked Questions
1
What is CVE-2021-22154?
CVE-2021-22154 is an Information Disclosure vulnerability in the Management Console component of BlackBerry UEM.
2
How severe is CVE-2021-22154?
CVE-2021-22154 has a severity score of 5.3, which is considered medium.
3
Which versions of BlackBerry UEM are affected by CVE-2021-22154?
CVE-2021-22154 affects BlackBerry UEM versions 12.13.1 QF2 and earlier, and 12.12.1a QF6 and earlier.
4
What can an attacker potentially gain access to through CVE-2021-22154?
Through CVE-2021-22154, an attacker can potentially gain access to a victim's web history.
5
How can I fix CVE-2021-22154?
To fix CVE-2021-22154, it is recommended to update to BlackBerry UEM version 12.13.1 QF3 or 12.12.1a QF7, or later versions.