« Back to list

CVE-2017-9368

Status: ModifiedHigh (7.5)—

An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-9368",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secure@blackberry.com",
      "affectedData": [
        {
          "vendor": "BlackBerry",
          "product": "Workspaces Server",
          "versions": [
            {
              "status": "affected",
              "version": "BlackBerry Workspaces Server components Appliance-X 1.11.0 to 1.11.2, vApp versions 5.6.0 to 5.6.6, and vApp versions 5.5.9 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-16T21:29:00.307",
  "references": [
    {
      "url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045696",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@blackberry.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/96542",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@blackberry.com"
    },
    {
      "url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045696",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/96542",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de divulgación de información en BlackBerry Workspaces Server podría resultar en un atacante obteniendo acceso al código fuente para las aplicaciones del lado del servidor manipulando una petición para archivos específicos."
    }
  ],
  "lastModified": "2026-06-17T01:27:58.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F375EEB-9B67-4E8C-B59D-5E45D5744AC9"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CBC4987-A09A-44AD-B691-59AB62ACC9EB"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "449009A5-0F54-41D5-BE49-EADE65F77CFF"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79496E2E-38D9-4707-987D-521FD417ABC4"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA490F11-2C67-4A29-A831-BB218E52779F"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED290A07-6623-49F1-BC2F-58696CEE45F5"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72F68629-73B5-41FB-8ABE-3B49FCCF3841"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1AFC2FF-5093-4761-B72A-8D22601A965F"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7FAC0CA-253B-4013-B89A-B180D95E3310"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67D6DDE0-5DEE-406B-B96A-6C7A203BB368"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "964BBFE6-AFCC-4577-8F84-D4F71D507060"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "416765A7-911E-4327-80F0-3CA4B2A09B2A"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFB80B3C-3EF0-427C-B9FE-DD54F248DD13"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF721FB8-0BA8-4792-B409-CE71CDCF5ACE"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1F96B35-BF5D-4254-A9EA-972997DD70CD"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55D0A794-854B-40FE-A95B-776D469F426E"
            },
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A47B0C9-6C09-4A5F-A473-C82618822041"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:blackberry:workspaces_appliance-x:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "693F0340-B3E0-48B5-8DFF-E77CC8E70315",
              "versionEndIncluding": "1.11.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@blackberry.com"
}