{"api_version":"1","generated_at":"2026-07-24T02:22:38+00:00","cve":"CVE-2016-3129","urls":{"html":"https://cve.report/CVE-2016-3129","api":"https://cve.report/api/cve/CVE-2016-3129.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-3129","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-3129"},"summary":{"title":"CVE-2016-3129","description":"A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.","state":"PUBLISHED","assigner":"blackberry","published_at":"2016-12-16 09:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","remote shell execution"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None","name":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BSRT-2016-008 Remote shell execution vulnerability affects Good Enterprise Mobility Server","mime":"application/octet-stream","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94959","name":"http://www.securityfocus.com/bid/94959","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Good Enterprise Mobility Server CVE-2016-3129 Arbitrary Command Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-3129","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-3129","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25","version":"affected BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"3129","vulnerable":"1","versionEndIncluding":"2.2.22.25","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"blackberry","cpe5":"good_enterprise_mobility_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"3129","cve":"CVE-2016-3129","epss":"0.019320000","percentile":"0.835260000","score_date":"2026-05-11","updated_at":"2026-05-12 00:01:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:47:57.227Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None"},{"name":"94959","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94959"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25","vendor":"n/a","versions":[{"status":"affected","version":"BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25"}]}],"datePublic":"2016-12-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell."}],"problemTypes":[{"descriptions":[{"description":"remote shell execution","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T10:57:01.000Z","orgId":"dbe78b00-5e7b-4fda-8748-329789ecfc5c","shortName":"blackberry"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None"},{"name":"94959","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94959"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@blackberry.com","ID":"CVE-2016-3129","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25","version":{"version_data":[{"version_value":"BlackBerry GEMS versions 2.1.5.3 to 2.2.22.25"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"remote shell execution"}]}]},"references":{"reference_data":[{"name":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None","refsource":"CONFIRM","url":"http://support.blackberry.com/kb/articleDetail?articleNumber=000038814&language=None"},{"name":"94959","refsource":"BID","url":"http://www.securityfocus.com/bid/94959"}]}}}},"cveMetadata":{"assignerOrgId":"dbe78b00-5e7b-4fda-8748-329789ecfc5c","assignerShortName":"blackberry","cveId":"CVE-2016-3129","datePublished":"2016-12-16T09:02:00.000Z","dateReserved":"2016-03-11T00:00:00.000Z","dateUpdated":"2024-08-05T23:47:57.227Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-12-16 09:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","remote shell execution"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:blackberry:good_enterprise_mobility_server:*:*:*:*:*:*:*:*","versionEndIncluding":"2.2.22.25","matchCriteriaId":"396E10E8-4D3F-461A-848D-6B7556F56C31"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"3129","Ordinal":"1","Title":"CVE-2016-3129","CVE":"CVE-2016-3129","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"3129","Ordinal":"1","NoteData":"A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.","Type":"Description","Title":"CVE-2016-3129"},{"CveYear":"2016","CveId":"3129","Ordinal":"2","NoteData":"2016-12-16","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"3129","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}