Vulnerability Description
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Unified Endpoint Management | <= 12.10.1a |
Related Weaknesses (CWE)
References
- http://support.blackberry.com/kb/articleDetail?articleNumber=000056241MitigationPatchVendor Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000056241MitigationPatchVendor Advisory
FAQ
What is CVE-2019-8999?
CVE-2019-8999 is a vulnerability with a CVSS score of 7.5 (HIGH). An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the ...
How severe is CVE-2019-8999?
CVE-2019-8999 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8999?
Check the references section above for vendor advisories and patch information. Affected products include: Blackberry Unified Endpoint Management.