The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
References
Link | Resource |
---|---|
http://www.blackberry.com/btsc/KB37573 | Vendor Advisory |
http://www.securitytracker.com/id/1034154 | |
http://www.blackberry.com/btsc/KB37573 | Vendor Advisory |
http://www.securitytracker.com/id/1034154 |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.blackberry.com/btsc/KB37573 - Vendor Advisory | |
References | () http://www.securitytracker.com/id/1034154 - |
Information
Published : 2015-11-19 11:59
Updated : 2024-11-21 02:30
NVD link : CVE-2015-4112
Mitre link : CVE-2015-4112
CVE.ORG link : CVE-2015-4112
JSON object : View
Products Affected
blackberry
- enterprise_server
CWE
CWE-254
7PK - Security Features