Vulnerability Description
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Enterprise Mobility Server | <= 2.8.17.29 |
Related Weaknesses (CWE)
References
- http://support.blackberry.com/kb/articleDetail?articleNumber=000051590&language=Vendor Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000051590&language=Vendor Advisory
FAQ
What is CVE-2018-8889?
CVE-2018-8889 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context ...
How severe is CVE-2018-8889?
CVE-2018-8889 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-8889?
Check the references section above for vendor advisories and patch information. Affected products include: Blackberry Enterprise Mobility Server.