The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
References
Link | Resource |
---|---|
http://www.blackberry.com/btsc/KB37573 | Vendor Advisory |
http://www.securitytracker.com/id/1034154 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-11-19 03:59
Updated : 2016-12-07 10:11
NVD link : CVE-2015-4112
Mitre link : CVE-2015-4112
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
blackberry
- enterprise_server