VULNERABILITY INTELLIGENCE
CVE-2017-9367
CVSS score9.8 CRITICAL
EPSS probability1.62%
CISA KEVNot currently listed
Published2017-10-16
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
Weakness classification
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Primary references
- secure@blackberry.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory