Junglewise Threat Intelligence

CVE-2017-3890: BlackBerry WatchDox Server reflected XSS in Appliance-X and vAPP

CVE-2017-3890 · Severity: medium · CVSS 6.1 · Published 2017-01-13

Vendors: Blackberry.

Executive brief

BlackBerry WatchDox (now Workspaces) is a secure file-sharing and collaboration platform. A vulnerability in its server components could allow an attacker to execute malicious scripts in a user's web browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the BlackBerry WatchDox Server (Workspaces) Appliance-X (v1.8.1 and earlier) and vAPP (v4.6.0 through 5.4.1) components. The flaw is caused by improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit this by persuading a user to follow a malicious link, resulting in the execution of arbitrary JavaScript in the context of the victim's browser session. This can be used to bypass same-origin policy protections, access cookies, or perform actions as the authenticated user.

Affected products

  • BlackBerry WatchDox Server Appliance-X 1.8.1 and earlier
  • BlackBerry WatchDox Server vAPP 4.6.0 to 5.4.1
  • BlackBerry Workspaces vAPP 4.6.0 to 5.4.1

Timeline

  • 2017-01-13: advisory: Initial NVD publication
  • 2017-01-13: disclosed: BlackBerry security advisory published

References