CVE-2018-8891
Last modified
CVE-2018-8891 is a vulnerability of currently unknown severity. Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Unified Endpoint Manager | < 12.9.1 |
References
- http://support.blackberry.com/kb/articleDetail?articleNumber=000054162Mitigation, Vendor Advisory
- http://support.blackberry.com/kb/articleDetail?articleNumber=000054162Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8891?
How severe is CVE-2018-8891?
How do I fix CVE-2018-8891?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-8882Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer…
- CVE-2018-8883Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read i…
- CVE-2018-8885screenresolution-mechanism in screen-resolution-extra 0.17.2…
- CVE-2018-8888A stored cross-site scripting (XSS) vulnerability in the Man…
- CVE-2018-8889A directory traversal vulnerability in the Connect Service o…
- CVE-2018-8890An information disclosure vulnerability in the Management Co…7.5
- CVE-2018-8892A cross-site request forgery (CSRF) vulnerability in the Man…
- CVE-2018-8893Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting …
- CVE-2018-8894In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sy…
- CVE-2018-8895In 2345 Security Guard 3.6, the driver file (2345DumpBlock.s…
- CVE-2018-8896In 2345 Security Guard 3.6, the driver file (2345DumpBlock.s…
- CVE-2018-8897A statement in the System Programming Guide of the Intel 64 …
Are you affected by CVE-2018-8891?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
