CVE-2011-0290

BlackBerry Enterprise Server 5.0.3 MR4 - Authenticated Account Hijacking and Denial of Service

Title source: llm
STIX 2.1

Description

The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.

References (6)

Core 6
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46370
Exploit, Vendor Advisory x_refsource_confirm
http://www.blackberry.com/btsc/KB28524
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50064
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1026179
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/76286
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70519

Scores

EPSS 0.0210
EPSS Percentile 79.8%

Details

CWE
CWE-264
Status published
Products (1)
rim/blackberry_enterprise_server 5.0.3
Published Oct 21, 2011
Tracked Since Feb 18, 2026