{"api_version":"1","generated_at":"2026-07-23T18:57:17+00:00","cve":"CVE-2009-0307","urls":{"html":"https://cve.report/CVE-2009-0307","api":"https://cve.report/api/cve/CVE-2009-0307.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0307","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0307"},"summary":{"title":"CVE-2009-0307","description":"Cross-site scripting (XSS) vulnerability in the \"Customize Statistics Page\" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-04-22 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969","name":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34573","name":"http://www.securityfocus.com/bid/34573","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"BlackBerry Enterprise Server MDS Connection Service Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2009/1090","name":"http://www.vupen.com/english/advisories/2009/1090","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022081","name":"http://www.securitytracker.com/id?1022081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Enterprise Server Input Validation Flaw in MDS Connection Service Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/34740","name":"http://secunia.com/advisories/34740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Enterprise Server MDS Connection Service Cross-Site Scripting - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/53772","name":"http://osvdb.org/53772","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0307","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0307","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.0","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"307","vulnerable":"1","versionEndIncluding":"4.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"*","cpe7":"mr4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:31:25.613Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1022081","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022081"},{"name":"34573","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34573"},{"name":"20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html"},{"name":"34740","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34740"},{"name":"53772","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/53772"},{"name":"ADV-2009-1090","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1090"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the \"Customize Statistics Page\" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-04-28T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1022081","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022081"},{"name":"34573","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34573"},{"name":"20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html"},{"name":"34740","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34740"},{"name":"53772","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/53772"},{"name":"ADV-2009-1090","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1090"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0307","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the \"Customize Statistics Page\" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1022081","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022081"},{"name":"34573","refsource":"BID","url":"http://www.securityfocus.com/bid/34573"},{"name":"20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html"},{"name":"34740","refsource":"SECUNIA","url":"http://secunia.com/advisories/34740"},{"name":"53772","refsource":"OSVDB","url":"http://osvdb.org/53772"},{"name":"ADV-2009-1090","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1090"},{"name":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0307","datePublished":"2009-04-22T18:00:00.000Z","dateReserved":"2009-01-27T00:00:00.000Z","dateUpdated":"2024-08-07T04:31:25.613Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-04-22 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:*:mr4:*:*:*:*:*:*","versionEndIncluding":"4.1.6","matchCriteriaId":"1200C916-4168-49E6-A0F4-665F6A5954F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0B7A2FFD-C840-459C-95C2-92FEDF341D5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.0:sp3:*:*:*:*:*:*","matchCriteriaId":"8E297652-3533-4B2B-BA9E-FDC452BAE650"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.0.3:*:*:*:*:*:*:*","matchCriteriaId":"B51FB6C5-1EA2-451E-A89B-9CE5EE3F8626"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1:*:*:*:*:*:*:*","matchCriteriaId":"C4ACEF3E-E394-45E2-B20F-8575C92A490F"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1:sp3:*:*:*:*:*:*","matchCriteriaId":"9F71618E-5CB6-41A7-9705-6AD4344CDEA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:*","matchCriteriaId":"E4BD344A-EE9C-4ECB-8CB1-35146FD6F056"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:*","matchCriteriaId":"B1694E42-9AA5-4503-9714-CBDE388481A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:*","matchCriteriaId":"16F378AF-E25B-4D60-AF7E-9E6FB228BF1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:*","matchCriteriaId":"265D8F90-96C3-4627-ABA5-994C25F70A45"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"307","Ordinal":"1","Title":"CVE-2009-0307","CVE":"CVE-2009-0307","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"307","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the \"Customize Statistics Page\" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.","Type":"Description","Title":"CVE-2009-0307"},{"CveYear":"2009","CveId":"307","Ordinal":"2","NoteData":"2009-04-22","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"307","Ordinal":"3","NoteData":"2009-04-28","Type":"Other","Title":"Modified"}]}}}