Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT screen.
References
Link | Resource |
---|---|
http://www.blackberry.com/btsc/KB38117 | Vendor Advisory |
http://www.securitytracker.com/id/1035568 |
Configurations
Information
Published : 2016-04-22 11:59
Updated : 2016-12-02 19:23
NVD link : CVE-2016-1916
Mitre link : CVE-2016-1916
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
blackberry
- enterprise_server