Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "8F375EEB-9B67-4E8C-B59D-5E45D5744AC9", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "7CBC4987-A09A-44AD-B691-59AB62ACC9EB", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "449009A5-0F54-41D5-BE49-EADE65F77CFF", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "79496E2E-38D9-4707-987D-521FD417ABC4", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "AA490F11-2C67-4A29-A831-BB218E52779F", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.5:*:*:*:*:*:*:*", "matchCriteriaId": "ED290A07-6623-49F1-BC2F-58696CEE45F5", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.6:*:*:*:*:*:*:*", "matchCriteriaId": "72F68629-73B5-41FB-8ABE-3B49FCCF3841", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.7:*:*:*:*:*:*:*", "matchCriteriaId": "C1AFC2FF-5093-4761-B72A-8D22601A965F", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.8:*:*:*:*:*:*:*", "matchCriteriaId": "C7FAC0CA-253B-4013-B89A-B180D95E3310", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.5.9:*:*:*:*:*:*:*", "matchCriteriaId": "67D6DDE0-5DEE-406B-B96A-6C7A203BB368", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "964BBFE6-AFCC-4577-8F84-D4F71D507060", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "416765A7-911E-4327-80F0-3CA4B2A09B2A", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "DFB80B3C-3EF0-427C-B9FE-DD54F248DD13", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "CF721FB8-0BA8-4792-B409-CE71CDCF5ACE", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.4:*:*:*:*:*:*:*", "matchCriteriaId": "C1F96B35-BF5D-4254-A9EA-972997DD70CD", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.5:*:*:*:*:*:*:*", "matchCriteriaId": "55D0A794-854B-40FE-A95B-776D469F426E", "vulnerable": true}, {"criteria": "cpe:2.3:a:blackberry:workspaces_vapp:5.6.6:*:*:*:*:*:*:*", "matchCriteriaId": "5A47B0C9-6C09-4A5F-A473-C82618822041", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:blackberry:workspaces_appliance-x:*:*:*:*:*:*:*:*", "matchCriteriaId": "693F0340-B3E0-48B5-8DFF-E77CC8E70315", "versionEndIncluding": "1.11.2", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request."}, {"lang": "es", "value": "Una vulnerabilidad de salto de directorio en BlackBerry Workspaces Server podr\u00eda permitir que un atacante ejecute o suba archivos arbitrarios, o que revele el contenido de archivos arbitrarios en cualquier parte del servidor web manipulando una URL con una petici\u00f3n POST manipulada."}], "id": "CVE-2017-9367", "lastModified": "2025-04-20T01:37:25.860", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2017-10-16T21:29:00.277", "references": [{"source": "secure@blackberry.com", "tags": ["Vendor Advisory"], "url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045696"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045696"}], "sourceIdentifier": "secure@blackberry.com", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-22"}], "source": "nvd@nist.gov", "type": "Primary"}]}