CVE-2016-3129: Blackberry Good Enterprise Mobility Server

Medium severity, CVSS 6.6. EPSS: 2.9% chance of exploitation in the next 30 days.

A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.

Affected products

  • Blackberry Good Enterprise Mobility Server: up to and including 2.2.22.25

Published 2016-12-16. Last modified 2026-06-17.