{"api_version":"1","generated_at":"2026-07-23T04:31:53+00:00","cve":"CVE-2017-9370","urls":{"html":"https://cve.report/CVE-2017-9370","api":"https://cve.report/api/cve/CVE-2017-9370.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9370","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9370"},"summary":{"title":"CVE-2017-9370","description":"An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.","state":"PUBLIC","assigner":"secure@blackberry.com","published_at":"2017-08-09 17:29:00","updated_at":"2017-08-24 13:12:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350","name":"http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"BSRT-2017-005 Vulnerability in Workspaces Server components impacts BlackBerry Workspaces SAML-IDP bridge","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9370","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9370","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9370","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"blackberry","cpe5":"workspaces","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"9370","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"blackberry","cpe5":"workspaces","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@blackberry.com","DATE_PUBLIC":"2017-08-09T00:00:00","ID":"CVE-2017-9370","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BlackBerry Workspaces Server; WatchDox by BlackBerry Server","version":{"version_data":[{"version_value":"Appliance-X versions 1.11.0 to 1.11.1"},{"version_value":"Appliance-X versions 1.6.0 to 1.10.2"},{"version_value":"vApp versions 5.6.0 to 5.6.4"},{"version_value":"vApp versions 5.5.0 to 5.5.8"},{"version_value":"vApp versions 5.1.0 to 5.4.8"}]}}]},"vendor_name":"BlackBerry"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information disclosure/elevation of privilege"}]}]},"references":{"reference_data":[{"name":"http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350","refsource":"CONFIRM","url":"http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000045350"}]}},"nvd":{"publishedDate":"2017-08-09 17:29:00","lastModifiedDate":"2017-08-24 13:12:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:blackberry:workspaces:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9370","Ordinal":"106383","Title":"CVE-2017-9370","CVE":"CVE-2017-9370","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9370","Ordinal":"1","NoteData":"An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9370","Ordinal":"2","NoteData":"2017-08-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9370","Ordinal":"3","NoteData":"2017-08-09","Type":"Other","Title":"Modified"}]}}}