Learn about CVE-2017-3894 affecting BlackBerry Unified Endpoint Manager and BES12. Discover the impact, affected versions, exploitation, and mitigation steps.
BlackBerry Unified Endpoint Manager and BES12 are affected by a stored cross-site scripting vulnerability that allows attackers to perform actions as a Management Console administrator.
Understanding CVE-2017-3894
A stored cross-site scripting vulnerability in BlackBerry Unified Endpoint Manager and BES12 enables attackers to execute actions using the privileges of a Management Console administrator.
What is CVE-2017-3894?
The Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, as well as all versions of BES12, have a vulnerability known as stored cross-site scripting (XSS). This vulnerability allows attackers to carry out actions using the privileges of a Management Console administrator by uploading a harmful script.
The Impact of CVE-2017-3894
Technical Details of CVE-2017-3894
A stored cross-site scripting vulnerability affecting BlackBerry Unified Endpoint Manager and BES12.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the CVE-2017-3894 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates