CVE-2017-9370
Estado: ModificadaAlta (8.8)—
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-9370",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secure@blackberry.com",
"affectedData": [
{
"vendor": "BlackBerry",
"product": "BlackBerry Workspaces Server; WatchDox by BlackBerry Server",
"versions": [
{
"status": "affected",
"version": "Appliance-X versions 1.11.0 to 1.11.1"
},
{
"status": "affected",
"version": "Appliance-X versions 1.6.0 to 1.10.2"
},
{
"status": "affected",
"version": "vApp versions 5.6.0 to 5.6.4"
},
{
"status": "affected",
"version": "vApp versions 5.5.0 to 5.5.8"
},
{
"status": "affected",
"version": "vApp versions 5.1.0 to 5.4.8"
}
]
}
]
}
],
"published": "2017-08-09T17:29:00.190",
"references": [
{
"url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350",
"tags": [
"Vendor Advisory"
],
"source": "secure@blackberry.com"
},
{
"url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server."
},
{
"lang": "es",
"value": "Una vulnerabilidad de relevavión de información o elevación de privilegios en BlackBerry Workspaces Server podría permitir que un atacante con acceso legítimo a BlackBerry Workspaces obtuviese acceso al espacio de trabajo de otro usuario mediante múltiples peticiones de inicio de sesión al servidor."
}
],
"lastModified": "2026-06-17T01:27:58.750",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:blackberry:workspaces:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8636A1D-6DC1-4DFF-BCDD-C6020D99A521"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@blackberry.com"
}