vendor:
BlackBerry Device Software
by:
599eme Man
7.5
CVSS
HIGH
Cross-Domain Information Disclosure
200
CWE
Product Name: BlackBerry Device Software
Affected Version From: BlackBerry Device Software
Affected Version To: BlackBerry Device Software
Patch Exists: NO
Related CWE:
CPE: a:research_in_motion:blackberry_device_software
Platforms Tested:
2010
BlackBerry Device Software Cross-Domain Information Disclosure Vulnerability
The BlackBerry Device Software is prone to a cross-domain information-disclosure vulnerability because the application's web browser fails to properly enforce the same-origin policy. An attacker can exploit this issue to access local files or content from a browser window in another domain or security zone. This may allow the attacker to obtain sensitive information or may aid in further attacks.
Mitigation:
No official mitigation or remediation is available for this vulnerability.