CVE-2014-1467
Summary
| CVE | CVE-2014-1467 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-14 13:10:30 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise through 5.0.4 MR6 log cleartext credentials during exception handling, which might allow context-dependent attackers to obtain sensitive information by reading a log file. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS: 0.002630000 probability, percentile 0.496180000 (date 2026-05-12)
Problem Types: CWE-255 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Blackberry | Blackberry Enterprise Service | 10.0 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.1.0 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.1.2 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.2.0 | All | All | All |
| Application | Blackberry | Blackberry Universal Device Service | 6.0 | All | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server Express | All | All | All | All |
| Application | Blackberry | Enterprise Server Express | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KB35647-BSRT-2014-002 Information disclosure vulnerability affects BlackBerry Enterprise Service 10, Universal Device Service 6 and BlackBerry Enterprise Server 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | www.blackberry.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.