A successful attack could result in remote code execution (RCE) on a smartphone running BlackBerry 6 software. An attacker could exploit the vulnerabilities to access the built-in media storage on a smartphone running BlackBerry 6. WebKit has access to data stored in the built-in media section as well as the media card (if present), but not the application storage of the BlackBerry smartphone because WebKit runs in a user mode process (a restricted process).
Immune Systems:
*BlackBerry Device Software versions earlier than 6.0
*BlackBerry 7 and later
*BlackBerry Enterprise Server
*BlackBerry Internet Service
*BlackBerry Desktop Manager
*BlackBerry Mobile Voice System
Security issues exist in the versions of the Apache Tomcat web server that some BlackBerry Enterprise Server components use to serve administration pages. The BlackBerry Administration Service, the BlackBerry Mobile Data System Connection Service, and the BlackBerry Monitoring Service use the Apache Tomcat web server.
These issues primarily affect the Apache Tomcat web server version that the BlackBerry Administration Service uses. Some minor issues impact the BlackBerry Mobile Data System Connection Service and the BlackBerry Monitoring Service. These issues do not affect BlackBerry messaging.
Vendor Status:
Blackberry had issued an update for this vulnerability