Check: 2013-B-0118
Windows 2012 IAVM:
2013-B-0118
(in version v1 r30)
Title
BlackBerry Enterprise Service (BES) Remote Code Execution Vulnerability (Cat II impact)
Discussion
Research in Motion has released a security advisory addressing a vulnerability in BlackBerry Enterprise Service (BES). To exploit this vulnerability, an attacker would use the Remote Method Invocation (RMI) interface to serve a malicious package to JBoss from a second server on the network that is not blocked by a firewall. If successfully exploited, this vulnerability would allow an attacker to execute arbitrary code using the privileges of the BES10 administration service account. .
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-40789
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |