BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
BID:48655
Info
BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
| Bugtraq ID: | 48655 |
| Class: | Unknown |
| CVE: |
CVE-2011-0287 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2011 12:00AM |
| Updated: | Jul 12 2011 12:00AM |
| Credit: | Richard Leach of NGSSecure |
| Vulnerable: |
Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.0 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server for Exchange 5.0 SP2 Research In Motion Blackberry Enterprise Server for Exchange 5.0 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.1 Research In Motion Blackberry Enterprise Server for Domino 5.0 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.0 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.3 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.0 Research In Motion Blackberry Enterprise Server 5.0.2 Research In Motion Blackberry Enterprise Server 5.0 |
| Not Vulnerable: | |
Discussion
BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
BlackBerry Enterprise Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks. Attackers may also leverage this issue to consume excessive resources to trigger a denial-of-service condition.
BlackBerry Enterprise Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks. Attackers may also leverage this issue to consume excessive resources to trigger a denial-of-service condition.
Exploit / POC
BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
BlackBerry Enterprise Server Administration API Information Disclosure Vulnerability
References:
References:
- Research In Motion Homepage (Research In Motion)
- KB27258 Vulnerability in a BlackBerry Enterprise Server component could allow in (Research in Motion)