Vulnerability Description
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Athoc | < 7.6_hf-567 |
Related Weaknesses (CWE)
References
- http://support.blackberry.com/kb/articleDetail?articleNumber=000047227Vendor Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000047227Vendor Advisory
FAQ
What is CVE-2019-8997?
CVE-2019-8997 is a vulnerability with a CVSS score of 5.9 (MEDIUM). An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local...
How severe is CVE-2019-8997?
CVE-2019-8997 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8997?
Check the references section above for vendor advisories and patch information. Affected products include: Blackberry Athoc.