CVE-2016-1916: Blackberry Enterprise Server
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT screen.
Affected products
- Blackberry Enterprise Server: up to and including 12.4
Published 2016-04-22. Last modified 2026-06-17.