PT-2015-6418 · Blackberry · Blackberry Enterprise Server

Publicado

2015-11-19

·

Atualizado

2016-12-07

·

CVE-2015-4112

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions BlackBerry Enterprise Server versions prior to 12.2
Description The issue is related to a "cross frame scripting" problem, where the Management Console in BlackBerry Enterprise Server does not properly restrict the use of FRAME elements. This makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Recommendations For versions prior to 12.2, update to version 12.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Management Console to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4112

Produtos afetados

Blackberry Enterprise Server