Impact
An insecure input validation (CWE-74) in the BlackBerry UEM Management Console allows an attacker to download arbitrary files from the server and may lead to a denial of service. The flaw enables bypassing normal request restrictions, giving unauthorized access to sensitive data that should not be publicly available. If exploited, this could compromise confidentiality and disrupt system availability by exhausting resources.
Affected Systems
The vulnerability exists in BlackBerry UEM 12.23.0 QF8 and all earlier releases of the Management Console. The affected component is the web‑based console that processes file‑related requests.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity issue, while the EPSS score of <1% suggests a low likelihood of real‑world exploitation and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description to involve sending crafted requests to the console over the network; the attacker would need network reachability to the console and access rights that allow the operation. Successful exploitation could allow arbitrary file download or trigger a denial of service by exhausting system resources.
OpenCVE Enrichment