Vulnerability Name: CVE-2009-0307 (CCN-49926) Assigned: 2009-04-17 Published: 2009-04-17 Updated: 2009-04-28 Summary: Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-79 Vulnerability Consequences: Gain Access References: Source: CCN Type: Full-Disclosure Mailing List, Fri Apr 17 2009 - 07:21:57 CDT ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service Source: FULLDISC Type: UNKNOWN20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service Source: MITRE Type: CNACVE-2009-0307 Source: OSVDB Type: UNKNOWN53772 Source: CCN Type: SA34740BlackBerry Enterprise Server MDS Connection Service Cross-Site Scripting Source: SECUNIA Type: Vendor Advisory34740 Source: CCN Type: SECTRACK ID: 1022081BlackBerry Enterprise Server Input Validation Flaw in MDS Connection Service Permits Cross-Site Scripting Attacks Source: CONFIRM Type: Vendor Advisoryhttp://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&sliceID=1&command=show&forward=nonthreadedKC&kcId=KB17969 Source: CCN Type: BlackBerry Security Advisory KB17969Cross site scripting vulnerability in the BlackBerry Enterprise Server MDS Connection Service Source: CCN Type: OSVDB ID: 53772BlackBerry Enterprise Server MDS Connection Service /admin/statistics/ConfigureStatistics Multiple Parameter XSS Source: BID Type: Exploit34573 Source: CCN Type: BID-34573BlackBerry Enterprise Server MDS Connection Service Cross Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN1022081 Source: VUPEN Type: UNKNOWNADV-2009-1090 Source: XF Type: UNKNOWNblackberry-mdsconnection-xss(49926) Vulnerable Configuration: Configuration 1 :cpe:/a:rim:blackberry_enterprise_server:4.0:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.0:sp3:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.0.3:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1:sp3:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:*:mr4:*:*:*:*:*:* (Version <= 4.1.6) Configuration CCN 1 :cpe:/a:rim:blackberry_enterprise_server:4.0:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.0:sp3:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.1.6:mr4:*:*:*:*:*:* OR cpe:/a:rim:blackberry_enterprise_server:4.0.3:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
rim blackberry enterprise server 4.0
rim blackberry enterprise server 4.0 sp3
rim blackberry enterprise server 4.0.3
rim blackberry enterprise server 4.1
rim blackberry enterprise server 4.1 sp3
rim blackberry enterprise server 4.1.3
rim blackberry enterprise server 4.1.4
rim blackberry enterprise server 4.1.5
rim blackberry enterprise server 4.1.6
rim blackberry enterprise server * mr4
rim blackberry enterprise server 4.0
rim blackberry enterprise server 4.1.3
rim blackberry enterprise server 4.1.5
rim blackberry enterprise server 4.1.4
rim blackberry enterprise server 4.0 sp3
rim blackberry enterprise server 4.1.6
rim blackberry enterprise server 4.1.6 mr4
rim blackberry enterprise server 4.0.3