Executive brief
BlackBerry WatchDox (now Workspaces) is a secure file-sharing and collaboration platform. A vulnerability in its server components could allow an attacker to execute malicious scripts in a user's web browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the BlackBerry WatchDox Server (Workspaces) Appliance-X (v1.8.1 and earlier) and vAPP (v4.6.0 through 5.4.1) components. The flaw is caused by improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit this by persuading a user to follow a malicious link, resulting in the execution of arbitrary JavaScript in the context of the victim's browser session. This can be used to bypass same-origin policy protections, access cookies, or perform actions as the authenticated user.
Affected products
- BlackBerry WatchDox Server Appliance-X 1.8.1 and earlier
- BlackBerry WatchDox Server vAPP 4.6.0 to 5.4.1
- BlackBerry Workspaces vAPP 4.6.0 to 5.4.1
Timeline
- 2017-01-13: advisory: Initial NVD publication
- 2017-01-13: disclosed: BlackBerry security advisory published