CVE-2015-4112
Published Nov 19, 2015
Last updated 8 years ago
Overview
- Description
- The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-254
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:blackberry:enterprise_server:12.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84168B45-9DAB-4403-AA76-4A9F5590FC19" }, { "criteria": "cpe:2.3:a:blackberry:enterprise_server:12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E213D153-A8E7-428B-B60B-65E8AD47128A" } ], "operator": "OR" } ] } ]