Impact
A DOM‑based Cross‑Site Scripting flaw exists in the web portals of BlackBerry AtHoc IWS versions before 7.21 HF‑734. The vulnerability allows a malicious actor to inject and execute arbitrary JavaScript while a user is browsing an AtHoc portal, potentially resulting in cookie theft, session hijacking, or execution of unwanted actions in the victim’s session. The weakness is a client‑side code injection flaw catalogued as CWE‑79.
Affected Systems
BlackBerry AtHoc IWS, specifically the AtHoc Web Portal component of the IWS platform. Versions earlier than 7.21 HF‑734 are affected; newer releases are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests low current exploitation likelihood. Because the attack requires the user to click a crafted link or access a malicious page, the attack vector is remote via the web interface, and the vulnerability is not listed in CISA’s KEV catalog. If exploited, the attacker can perform client‑side actions under the victim’s authenticated context, but cannot directly compromise the underlying server or elevate privileges.
OpenCVE Enrichment