Executive brief
A security vulnerability in BlackBerry Enterprise Server (BES) 12 could allow an attacker to intercept sensitive login information. By monitoring network traffic between the server's core components and its management console, an attacker could capture the usernames and passwords of administrators or regular users. This could lead to unauthorized access to the management system and potential compromise of the organization's mobile device management infrastructure.
Technical details
An information disclosure vulnerability exists in BlackBerry Enterprise Server (BES) versions 12 through 12.5.2. The flaw is located within the communication channel between the BES Core and the Management Console. A remote attacker positioned to perform network sniffing (e.g., via a man-in-the-middle position) can intercept unencrypted or insufficiently protected traffic during login attempts. This allows the attacker to obtain plaintext local or domain credentials for administrator or user accounts. The vulnerability is classified under CWE-200 (Information Exposure) and CWE-255 (Credentials Management Errors). Users are advised to upgrade to a patched version of BES to ensure secure communication between internal components.
Affected products
- BlackBerry Enterprise Service (BES) 12 12 through 12.5.2
Timeline
- 2017-01-13: disclosed
- 2017-01-13: advisory