CVE-2015-4112: Medium severity blackberry enterprise service vulnerability
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4112?
CVE-2015-4112 has a medium severity rating due to its potential for clickjacking attacks.
How do I fix CVE-2015-4112?
To mitigate CVE-2015-4112, upgrade to BlackBerry Enterprise Server version 12.2 or later.
What impact does CVE-2015-4112 have on my system?
CVE-2015-4112 allows attackers to perform clickjacking attacks, which can compromise user interactions with the Management Console.
Which versions of BlackBerry Enterprise Server are affected by CVE-2015-4112?
CVE-2015-4112 affects BlackBerry Enterprise Server versions 12.0 and 12.1.
Is there a workaround for CVE-2015-4112 until I can update?
There are no officially recommended workarounds for CVE-2015-4112; updating to the latest version is advised.