CVE Vulnerabilities

CVE-2013-3693

Published: Oct 11, 2013 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.9 HIGH
AV:A/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.

Affected Software

Name Vendor Start Version End Version
Blackberry_enterprise_service Blackberry 10.0 (including) 10.0 (including)
Blackberry_enterprise_service Blackberry 10.1.0 (including) 10.1.0 (including)
Blackberry_enterprise_service Blackberry 10.1.2 (including) 10.1.2 (including)

References