Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1914

Опубликовано: 13 апр. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:blackberry:blackberry_enterprise_service:*:*:*:*:*:*:*:*
Версия до 12.3.1 (включая)

EPSS

Процентиль: 87%
0.03185
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

EPSS

Процентиль: 87%
0.03185
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-89