Vulnerabilities in Apache Tomcat implementation impact BlackBerry Enterprise Server components
20 Apr. 2010
Summary
These issues may result in a Denial of Service (DoS) impacting the ability of the affected components to serve administration pages. There is a more limited potential for these issues to result in information disclosure or Cross-Site Scripting (XSS) on the affected components.
Vulnerable Systems:
*BlackBerry Enterprise Server Express versions 5.0.1 through 5.0.2 MR1 for Microsoft Exchange
*BlackBerry Enterprise Server Express version 5.0.2 for IBM Lotus Domino
*BlackBerry Enterprise Server versions 4.1.4 through 5.0.2 MR1 for Microsoft Exchange
*BlackBerry Enterprise Server versions 4.1.4 through 5.0.2 for IBM Lotus Domino
*BlackBerry Enterprise Server versions 4.1.4 through 5.0.1 for Novell GroupWise
Immune Systems:
* BlackBerry Device Software
* BlackBerry Desktop Software
* BlackBerry Internet Service
Security issues exist in the versions of the Apache Tomcat web server that some BlackBerry Enterprise Server components use to serve administration pages. The BlackBerry Administration Service, the BlackBerry Mobile Data System Connection Service, and the BlackBerry Monitoring Service use the Apache Tomcat web server.
These issues primarily affect the Apache Tomcat web server version that the BlackBerry Administration Service uses. Some minor issues impact the BlackBerry Mobile Data System Connection Service and the BlackBerry Monitoring Service. These issues do not affect BlackBerry messaging.
Vendor Status:
Blackberry had issued an update for this vulnerability