CVE-2011-0290
Summary
| CVE | CVE-2011-0290 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-21 10:55:00 UTC |
| Updated | 2017-08-17 01:33:00 UTC |
| Description | The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lotus | Domino | All | All | All | All |
| Application | Lotus | Domino | All | All | All | All |
| Application | Microsoft | Exchange Server | All | All | All | All |
| Application | Microsoft | Exchange Server | All | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 5.0.3 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 5.0.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| BlackBerry Enterprise Server Collaboration Service Bug Lets Remote Users Impersonate Intra-organization Messages - SecurityTracker | SECTRACK | securitytracker.com | |
| 76286 | OSVDB | www.osvdb.org | |
| KB28524-Vulnerability in a component of the BlackBerry Enterprise Server could allow one enterprise instant messaging user to impersonate another | CONFIRM | www.blackberry.com | Exploit, Vendor Advisory |
| BlackBerry Enterprise Server Instant Messaging User Impersonation Vulnerability - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.