Information disclosure in BlackBerry Workspaces Appliance-X and BlackBerry Workspaces vApp - CVE-2017-9368
Published: October 17, 2017
Vulnerability details
The weakness exists in a file server API due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP GET requests to the API, trick the victim into following it and gain access to source code for server-side applications.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
BlackBerry Workspaces vApp
How to mitigate CVE-2017-9368
Update vApp to version 5.7.2.