BlackBerry Enterprise Server MDS Connection Service Cross Site Scripting(XSS) Vulnerability
23 Apr. 2012
Summary
This advisory describes a security issue whereby the MDS Connection Service of the BlackBerry Enterprise Server is susceptible to a potential cross site scripting vulnerability. The issue relates to the handling of malformed URLs
Credit:
The information has been provided by Ken Millar,Michael Thumann ,Martin O'Neal and Stephen de Vries.
Vulnerable Systems:
*BlackBerry Enterprise Server software version 4.1.6 MR4 and earlier
A security vulnerability exists in the MDS Connection Service of the BlackBerry Enterprise Server Version 4.1.6 MR4 and earlier. This vulnerability could enable externally supplied scripts to be executed in the security context of the user administering the MDS Connection Service using the BlackBerry MDS Connection Service administrative web page on port 8080 .
Vendor Status:
Blackberry had issued an update for this vulnerability