← Vulnerability feed

Vulnerability record · CVE-2017-3894 · published 10 May 2017

CVE-2017-3894: Blackberry enterprise service cross-site scripting vulnerability

Blackberry · Enterprise Service

A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target administrator to view the specific location of the malicious script within the Management Console.

6.1 CVSS 3.0 Medium EPSS 0.85% · top 43.6% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target administrator to view the specific location of the malicious script within the Management Console.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3894 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-18084Blackberry unified endpoint manager cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Sc…EPSS 0.25%8.2CVE-2016-3128Blackberry enterprise service vulnerabilityA spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device…EPSS 1.9%8.1CVE-2016-3130Blackberry enterprise service information exposure vulnerabilityAn information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote atta…EPSS 2.1%7.5CVE-2018-8890Blackberry unified endpoint manager information exposure vulnerabilityAn information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user…EPSS 1.1%6.5CVE-2018-8892Blackberry unified endpoint manager cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to…EPSS 0.41%6.1CVE-2017-17442Blackberry unified endpoint manager cross-site scripting vulnerabilityIn BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execu…EPSS 0.91%5.9CVE-2026-18085Blackberry unified endpoint manager injection vulnerabilityAn Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Po…EPSS 0.26%5.5CVE-2020-6933Blackberry unified endpoint manager improper input validation vulnerabilityAn improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and ear…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2017-3894), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.