Show filters
80 Total Results
Displaying 51-60 of 80
Sort by:
Attacker Value
Unknown
CVE-2016-1915
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.
0
Attacker Value
Unknown
CVE-2016-1914
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
0
Attacker Value
Unknown
CVE-2016-3127
Disclosure Date: March 03, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server.
0
Attacker Value
Unknown
CVE-2016-3128
Disclosure Date: January 13, 2017 (last updated November 25, 2024)
A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to the BES by gaining access to specific information about a device that was legitimately enrolled on the BES.
0
Attacker Value
Unknown
CVE-2017-3890
Disclosure Date: January 13, 2017 (last updated November 25, 2024)
A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.
0
Attacker Value
Unknown
CVE-2016-3130
Disclosure Date: January 13, 2017 (last updated November 25, 2024)
An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domain credentials of an administrator or user account by sniffing traffic between the two elements during a login attempt.
0
Attacker Value
Unknown
CVE-2016-3129
Disclosure Date: December 16, 2016 (last updated November 25, 2024)
A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.
0
Attacker Value
Unknown
CVE-2016-3126
Disclosure Date: April 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2016-1916
Disclosure Date: April 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT screen.
0
Attacker Value
Unknown
CVE-2016-1917
Disclosure Date: April 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1918.
0