Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, which might facilitate loading of malware.
https://exchange.xforce.ibmcloud.com/vulnerabilities/35442
http://www.praetoriang.net/presentations/blackjack.html
http://www.blackberry.com/btsc/articles/968/KB05499_f.SAL_Public.html