SB2017101705 - Multiple vulnerabilities in Blackberry Workspaces Server



SB2017101705 - Multiple vulnerabilities in Blackberry Workspaces Server

Published: October 17, 2017

Security Bulletin ID SB2017101705
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2017-9368)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists in a file server API due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP GET requests to the API, trick the victim into following it and gain access to source code for server-side applications.

Successful exploitation of the vulnerability results in information disclosure.


2) Directory traversal (CVE-ID: CVE-2017-9367)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to directory traversal. A remote attacker can send a specially crafted POST request, upload a web shell to the server’s webroot, execute arbitrary files, or reveal the content of arbitrary files anywhere on the web server.

Successful exploitation of the vulnerability may result in system compromise.


Remediation

Install update from vendor's website.