CVE-2016-1918: XSS
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1918?
CVE-2016-1918 has been rated as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
What systems are affected by CVE-2016-1918?
CVE-2016-1918 affects BlackBerry Enterprise Server versions prior to 12.4.1.
How do I fix CVE-2016-1918?
To fix CVE-2016-1918, upgrade your BlackBerry Enterprise Server software to version 12.4.1 or later.
What type of vulnerability is CVE-2016-1918?
CVE-2016-1918 is a cross-site scripting (XSS) vulnerability affecting the Management Console of the BlackBerry Enterprise Server.
Can CVE-2016-1918 allow remote code execution?
CVE-2016-1918 does not allow remote code execution but enables attackers to inject arbitrary web script or HTML.