CVE-2017-9367
Last modified
CVE-2017-9367 is a vulnerability of currently unknown severity. A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.. EPSS estimates a 1.62% chance of exploitation in the next 30 days.
Description
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Workspaces Vapp | 5.5.0 |
| Blackberry | Workspaces Vapp | 5.5.1 |
| Blackberry | Workspaces Vapp | 5.5.2 |
| Blackberry | Workspaces Vapp | 5.5.3 |
| Blackberry | Workspaces Vapp | 5.5.4 |
| Blackberry | Workspaces Vapp | 5.5.5 |
| Blackberry | Workspaces Vapp | 5.5.6 |
| Blackberry | Workspaces Vapp | 5.5.7 |
| Blackberry | Workspaces Vapp | 5.5.8 |
| Blackberry | Workspaces Vapp | 5.5.9 |
| Blackberry | Workspaces Vapp | 5.6.0 |
| Blackberry | Workspaces Vapp | 5.6.1 |
| Blackberry | Workspaces Vapp | 5.6.2 |
| Blackberry | Workspaces Vapp | 5.6.3 |
| Blackberry | Workspaces Vapp | 5.6.4 |
| Blackberry | Workspaces Vapp | 5.6.5 |
| Blackberry | Workspaces Vapp | 5.6.6 |
| Blackberry | Workspaces Appliance-X | <= 1.11.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9367?
How severe is CVE-2017-9367?
How do I fix CVE-2017-9367?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9361WebsiteBaker v2.10.0 has a stored XSS vulnerability in /acco…
- CVE-2017-9362ManageEngine ServiceDesk Plus before 9312 contains an XML in…
- CVE-2017-9363Untrusted Java serialization in Soffid IAM console before 1.…
- CVE-2017-9364Unrestricted File Upload exists in BigTree CMS through 4.2.1…
- CVE-2017-9365CSRF exists in BigTree CMS through 4.2.18 with the force par…
- CVE-2017-9366Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scri…
- CVE-2017-9368An information disclosure vulnerability in the BlackBerry Wo…
- CVE-2017-9369In BlackBerry QNX Software Development Platform (SDP) 6.6.0 …3.8
- CVE-2017-9370An information disclosure / elevation of privilege vulnerabi…
- CVE-2017-9371In BlackBerry QNX Software Development Platform (SDP) 6.6.0 …2.6
- CVE-2017-9372PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 a…
- CVE-2017-9373Memory leak in QEMU (aka Quick Emulator), when built with ID…5.5
Are you affected by CVE-2017-9367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
