Impact
Improper neutralization of input during page generation in the BlackBerry UEM Management Console allows a remote attacker to inject malicious scripts. The attack could lead to execution of arbitrary client‑side code, potentially stealing session cookies or hijacking authenticated users. The weakness is a classic client‑side injection (CWE‑79).
Affected Systems
BlackBerry UEM 12.23.0 QF8 or earlier is vulnerable. The affected vendor is BlackBerry, and only the UEM product is impacted.
Risk and Exploitability
The CVSS score of 8.6 reflects high impact and medium exploitability. The EPSS score is below 1%, indicating a low probability of widespread exploitation at the time of this analysis, and the vulnerability is not listed in CISA KEV. The likely attack vector is an attacker who gains access to the web console, either via authenticated login or local system compromise. No special privileges beyond console access appear required for exploitation.
OpenCVE Enrichment