Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 18th, 2011, 07:31 GMT · By

Information Disclosure Vulnerability Patched in BlackBerry Enterprise Server

SHARE:

Adjust text size:


Blackberry Enterprise Server security updates released
Enlarge picture
RIM has released security updates for its BlackBerry Enterprise Server (BES) product in order to address an information disclosure and denial of service flaw.

The vulnerability, CVE-2011-0287, is located in the BlackBerry Administration API component which passes requests to the BlackBerry Administration Service.

"A vulnerability exists in the BlackBerry Administration API which could allow an attacker to read files that contain only printable characters on the BlackBerry Enterprise Server, including unencrypted text files," RIM says in its official advisory.

Binary file formats are not affected and the impact is limited by the API component's access level. The vulnerability bears a score of 4.8 on the CVSS severity scale and successful exploitation can also result in a denial of service condition.

Affected products include BlackBerry® Enterprise Server version 5.0.0 for Microsoft Exchange, IBM Lotus Domino and Novell GroupWise (with the BlackBerry® Administration API component installed as an option only); BlackBerry® Enterprise Server Express 5.0.0 for Microsoft Exchange and IBM Lotus Domino (with the BlackBerry® Administration API component installed as an option only); BlackBerry® Enterprise Server Express versions 5.0.1, 5.0.2 and 5.0.3 for Microsoft Exchange; BlackBerry® Enterprise Server Express versions 5.0.2 and 5.0.3 for IBM Lotus Domino; BlackBerry® Enterprise Server versions 5.0.1, 5.0.2 and 5.0.3 for Microsoft Exchange and IBM Lotus Domino; and BlackBerry® Enterprise Server versions 5.0.1 for GroupWise.

Updates are only available for the 5.0.1, 5.0.2 and 5.0.3 versions of the server. Users running 5.0.0 or older versions are advised to upgrade.

In addition to deploying the patches as soon as possible, and as a matter of security best practices, administrators are advised to deploy BES in a segmented network configuration. This involves running each component on a separate computer and having those computers operate on their own network segments.

Such a measure has the benefit of restricting the compromise to a single computer instead of endangering the entire network and BES. RIM credits Richard Leach of NGSSecure for reporting the vulnerability.

TELL US WHAT YOU THINK:

1,048 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


BlackBerry Hacked via Drive-By Download at Pwn2Own

RIM Fixes Vulnerabilities in BlackBerry OS and BlackBerry Enterprise Server

RIM Patches Critical PDF Vulnerability in BlackBerry Enterprise Server

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM