PT-2017-8347 · Blackberry · Blackberry Enterprise Server
Published
2017-01-13
·
Updated
2017-02-03
·
CVE-2016-3130
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BlackBerry Enterprise Server versions 12 through 12.5.2
Description
An information disclosure issue in the Core and Management Console of BlackBerry Enterprise Server allows remote attackers to obtain local or domain credentials of an administrator or user account by sniffing traffic between the two elements during a login attempt.
Recommendations
For versions 12 through 12.5.2, update to a version that contains a fix for this issue to prevent remote attackers from obtaining sensitive credentials.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackberry Enterprise Server