CVE-2013-3693
high
CVSS v3
—
CVSS v2
7.9
VIR risk
7.9
Description
The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://secunia.com/advisories/55187
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| blackberry | blackberry_enterprise_service | 10.0 | |
| blackberry | blackberry_enterprise_service | 10.1.0 | |
| blackberry | blackberry_enterprise_service | 10.1.2 | |
References
- http://btsc.webapps.blackberry.com/btsc/viewdocument.do%3Bjsessionid=1C7CE6911426BCFAF2A80C3834F4DF0F?externalId=KB35139&sliceId=1&cmd=displayKC&docType=kc&noCount=true&ViewedDocsListHelper=com.kanisa.apps.common.BaseViewedDocsListHelperImpl
- http://secunia.com/advisories/55187
- http://btsc.webapps.blackberry.com/btsc/viewdocument.do%3Bjsessionid=1C7CE6911426BCFAF2A80C3834F4DF0F?externalId=KB35139&sliceId=1&cmd=displayKC&docType=kc&noCount=true&ViewedDocsListHelper=com.kanisa.apps.common.BaseViewedDocsListHelperImpl
- http://secunia.com/advisories/55187
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.