{"api_version":"1","generated_at":"2026-07-23T19:40:20+00:00","cve":"CVE-2011-0290","urls":{"html":"https://cve.report/CVE-2011-0290","api":"https://cve.report/api/cve/CVE-2011-0290.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0290","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0290"},"summary":{"title":"CVE-2011-0290","description":"The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-10-21 10:55:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/70519","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/70519","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/50064","name":"http://www.securityfocus.com/bid/50064","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/46370","name":"http://secunia.com/advisories/46370","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Enterprise Server Instant Messaging User Impersonation Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1026179","name":"http://securitytracker.com/id?1026179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Enterprise Server Collaboration Service Bug Lets Remote Users Impersonate Intra-organization Messages - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/76286","name":"http://www.osvdb.org/76286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.blackberry.com/btsc/KB28524","name":"http://www.blackberry.com/btsc/KB28524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"KB28524-Vulnerability in a component of the BlackBerry Enterprise Server could allow one enterprise instant messaging user to impersonate another","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0290","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0290","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"290","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lotus","cpe5":"domino","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"290","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"290","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"5.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:51:07.885Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"46370","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/46370"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/KB28524"},{"name":"50064","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/50064"},{"name":"1026179","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1026179"},{"name":"76286","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/76286"},{"name":"bes-collaboration-service-spoofing(70519)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/70519"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"46370","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/46370"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/KB28524"},{"name":"50064","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/50064"},{"name":"1026179","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1026179"},{"name":"76286","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/76286"},{"name":"bes-collaboration-service-spoofing(70519)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/70519"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-0290","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"46370","refsource":"SECUNIA","url":"http://secunia.com/advisories/46370"},{"name":"http://www.blackberry.com/btsc/KB28524","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/KB28524"},{"name":"50064","refsource":"BID","url":"http://www.securityfocus.com/bid/50064"},{"name":"1026179","refsource":"SECTRACK","url":"http://securitytracker.com/id?1026179"},{"name":"76286","refsource":"OSVDB","url":"http://www.osvdb.org/76286"},{"name":"bes-collaboration-service-spoofing(70519)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/70519"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-0290","datePublished":"2011-10-21T10:00:00.000Z","dateReserved":"2011-01-06T00:00:00.000Z","dateUpdated":"2024-08-06T21:51:07.885Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-10-21 10:55:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:5.0.3:*:*:*:*:*:*:*","matchCriteriaId":"11FF9320-7C94-4700-81A8-E7D7694EB97D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:lotus:domino:*:*:*:*:*:*:*:*","matchCriteriaId":"EB1DDF69-2820-4ADA-BB83-1E9704AF3CC6"},{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*","matchCriteriaId":"261FB692-DD0F-494F-A25A-AFCC00BE4585"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"290","Ordinal":"1","Title":"CVE-2011-0290","CVE":"CVE-2011-0290","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"290","Ordinal":"1","NoteData":"The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.","Type":"Description","Title":"CVE-2011-0290"},{"CveYear":"2011","CveId":"290","Ordinal":"2","NoteData":"2011-10-21","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"290","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}