← Vulnerability feed

Vulnerability record · CVE-2020-6933 · published 14 October 2020

CVE-2020-6933: Blackberry unified endpoint manager improper input validation vulnerability

Blackberry · Unified Endpoint Manager

An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service.

5.5 CVSS 3.1 Medium EPSS 0.27% · top 82.2% CWE-20 · Improper input validation
5.5CVSS 3.1 base score, v2 2.1
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-18084Blackberry unified endpoint manager cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Sc…EPSS 0.25%7.5CVE-2018-8890Blackberry unified endpoint manager information exposure vulnerabilityAn information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user…EPSS 1.1%6.5CVE-2018-8892Blackberry unified endpoint manager cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to…EPSS 0.41%6.1CVE-2017-17442Blackberry unified endpoint manager cross-site scripting vulnerabilityIn BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execu…EPSS 0.91%6.1CVE-2017-3894Blackberry enterprise service cross-site scripting vulnerabilityA stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all vers…EPSS 0.85%5.9CVE-2026-18085Blackberry unified endpoint manager injection vulnerabilityAn Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Po…EPSS 0.26%4.8CVE-2018-8888Blackberry unified endpoint manager cross-site scripting vulnerabilityA stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker t…EPSS 0.51%4.8CVE-2018-8891Blackberry unified endpoint manager cross-site scripting vulnerabilityMultiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an at…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2020-6933), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.