#VU8850 Directory traversal in BlackBerry Workspaces Appliance-X and BlackBerry Workspaces vApp


Published: 2017-10-17

Vulnerability identifier: #VU8850

Vulnerability risk: Low

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-9367

CWE-ID: CWE-22

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
BlackBerry Workspaces Appliance-X
Server applications / Other server solutions
BlackBerry Workspaces vApp
Server applications / Other server solutions

Vendor: BlackBerry

Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to directory traversal. A remote attacker can send a specially crafted POST request, upload a web shell to the server’s webroot, execute arbitrary files, or reveal the content of arbitrary files anywhere on the web server.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation
Update Appliance-X to version 1.12.0.
Update vApp to version 5.7.2.

Vulnerable software versions

BlackBerry Workspaces Appliance-X: 1.7.0 - 1.11.2

BlackBerry Workspaces vApp: 5.5.9 - 5.6.6


External links
http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045696


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability