CVE-2014-1469
Summary
| CVE | CVE-2014-1469 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-18 11:15:25 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Blackberry | Blackberry Enterprise Service | 10.0 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.1.0 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.1.2 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.2.0 | All | All | All |
| Application | Blackberry | Blackberry Enterprise Service | 10.2.1 | All | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server | All | mr6 | All | All |
| Application | Blackberry | Enterprise Server Express | 5.0.4 | All | All | All |
| Application | Blackberry | Enterprise Server Express | 5.0.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KB36175-BSRT-2014-007 Information disclosure vulnerability affects BlackBerry Enterprise Service 10 and BlackBerry Enterprise Server 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | www.blackberry.com | Patch, Vendor Advisory |
| BlackBerry Multiple Products Exception Handling Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SA60154 - BlackBerry Enterprise Server / Service Credentials Logging Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.