CVE-2013-3693

high
Published 2013-10-11 · Modified 2026-04-29
CVSS v3
CVSS v2
7.9
VIR risk
7.9

Description

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/55187

Application impact

VendorProductVersionsFixed
blackberryblackberry_enterprise_service10.0
blackberryblackberry_enterprise_service10.1.0
blackberryblackberry_enterprise_service10.1.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.