#VU8849 Information disclosure in BlackBerry Workspaces Appliance-X and BlackBerry Workspaces vApp - CVE-2017-9368
Published: October 17, 2017
BlackBerry Workspaces Appliance-X
BlackBerry Workspaces vApp
BlackBerry
Description
The weakness exists in a file server API due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP GET requests to the API, trick the victim into following it and gain access to source code for server-side applications.
Successful exploitation of the vulnerability results in information disclosure.
Remediation
Update vApp to version 5.7.2.