PT-2010-5175 · Blackberry · Blackberry Device
Published
2010-10-14
·
Updated
2010-10-15
·
CVE-2010-3934
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BlackBerry Device Software version 5.0.0.593
Description
The browser does not properly restrict cross-domain execution of JavaScript, allowing remote attackers to bypass the Same Origin Policy. This can be achieved via vectors related to a
window.open call and an IFRAME element.Recommendations
For BlackBerry Device Software version 5.0.0.593, consider restricting the use of JavaScript in the browser until a patch is available. As a temporary workaround, avoid using the
window.open function and IFRAME elements in conjunction, as these are related to the bypassing of the Same Origin Policy.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blackberry Device