CVE-2020-6932

An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blackberry:qnx_software_development_platform:*:*:*:*:*:*:*:*

History

22 Aug 2025, 16:15

Type Values Removed Values Added
CWE CWE-150
CVSS v2 : 10.0
v3 : 9.8
v2 : 10.0
v3 : 10.0

21 Nov 2024, 05:36

Type Values Removed Values Added
References () http://support.blackberry.com/kb/articleDetail?articleNumber=000061411 - Vendor Advisory () http://support.blackberry.com/kb/articleDetail?articleNumber=000061411 - Vendor Advisory

Information

Published : 2020-08-12 13:15

Updated : 2025-08-22 16:15


NVD link : CVE-2020-6932

Mitre link : CVE-2020-6932

CVE.ORG link : CVE-2020-6932


JSON object : View

Products Affected

blackberry

  • qnx_software_development_platform
CWE
CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

NVD-CWE-noinfo