SB2017101705 - Multiple vulnerabilities in Blackberry Workspaces Server
Published: October 17, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-9368)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The weakness exists in a file server API due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP GET requests to the API, trick the victim into following it and gain access to source code for server-side applications.
Successful exploitation of the vulnerability results in information disclosure.
2) Directory traversal (CVE-ID: CVE-2017-9367)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists due to directory traversal. A remote attacker can send a specially crafted POST request, upload a web shell to the server’s webroot, execute arbitrary files, or reveal the content of arbitrary files anywhere on the web server.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Install update from vendor's website.