CVE-2011-0286
Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server…
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject arbitrary web script or HTML via the displayErrorMessage parameter in a ManageDevices action.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- rim/blackberry enterprise server · rim/blackberry enterprise server express
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/44183Vendor Advisory
- http://securitytracker.com/id?1025356
- http://www.blackberry.com/btsc/KB26296Vendor Advisory
- http://www.cybsec.com/vuln/CYBSEC_Advisory_2011_0401_Cross_Site_Scripting_XSS_in_Blackberry_WebDesktop.pdfExploit
- http://www.securityfocus.com/bid/47324
- http://www.vupen.com/english/advisories/2011/0971Vendor Advisory
- http://secunia.com/advisories/44183Vendor Advisory
- http://securitytracker.com/id?1025356
- http://www.blackberry.com/btsc/KB26296Vendor Advisory
- http://www.cybsec.com/vuln/CYBSEC_Advisory_2011_0401_Cross_Site_Scripting_XSS_in_Blackberry_WebDesktop.pdfExploit
- http://www.securityfocus.com/bid/47324
- http://www.vupen.com/english/advisories/2011/0971Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.