CVE-2016-1915: XSS
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1915?
CVE-2016-1915 has a medium severity level, allowing remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2016-1915?
To address CVE-2016-1915, update BlackBerry Enterprise Server to version 12.4 or later.
What platforms are affected by CVE-2016-1915?
CVE-2016-1915 affects BlackBerry Enterprise Server 12 (BES12) Self-Service versions prior to 12.4.
What impact does CVE-2016-1915 have on users?
CVE-2016-1915 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user data and session security.
Is authentication required to exploit CVE-2016-1915?
No, CVE-2016-1915 can be exploited remotely without authentication, making it a significant security risk.