BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability
BID:50064
Info
BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability
| Bugtraq ID: | 50064 |
| Class: | Design Error |
| CVE: |
CVE-2011-0290 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Oct 11 2011 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR4 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 MR4 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 MR3 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 |
| Not Vulnerable: | |
Discussion
BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability
BlackBerry Collaboration Service of BlackBerry Enterprise Server is prone to a security-bypass vulnerability because the application fails to properly authenticate users.
Successfully exploiting this issue allows attackers to impersonate other legitimate users within an organization, which will aid in further attacks.
This issue affects the following:
BlackBerry Enterprise Server for Microsoft Exchange versions 5.0.3 through 5.0.3 MR4
BlackBerry Enterprise Server for IBM Lotus Domino versions 5.0.3 through 5.0.3 MR4
BlackBerry Collaboration Service of BlackBerry Enterprise Server is prone to a security-bypass vulnerability because the application fails to properly authenticate users.
Successfully exploiting this issue allows attackers to impersonate other legitimate users within an organization, which will aid in further attacks.
This issue affects the following:
BlackBerry Enterprise Server for Microsoft Exchange versions 5.0.3 through 5.0.3 MR4
BlackBerry Enterprise Server for IBM Lotus Domino versions 5.0.3 through 5.0.3 MR4
Exploit / POC
BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
BlackBerry Collaboration Service User Authentication Security Bypass Vulnerability
References:
References:
- Vendor Homepage (Research In Motion)
- Vulnerability in a component of the BlackBerry Enterprise Server could allow one (Research In Motion )