CVE-2017-3890: XSS
A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3890?
The severity of CVE-2017-3890 is classified as medium with a score of 6.1.
How do I fix CVE-2017-3890?
To fix CVE-2017-3890, upgrade the affected BlackBerry WatchDox Server components Appliance-X to version 1.8.2 or higher and vAPP to versions above 5.4.1.
What types of products are affected by CVE-2017-3890?
CVE-2017-3890 affects BlackBerry Appliance-X version 1.8.1 and earlier, along with BlackBerry Workspaces vAPP versions 4.6.0 to 5.4.1.
What kind of vulnerability is CVE-2017-3890?
CVE-2017-3890 is a reflected cross-site scripting (XSS) vulnerability that allows remote attackers to execute scripts in a user's browser.
Who can exploit CVE-2017-3890?
CVE-2017-3890 can be exploited by remote attackers who can persuade users to click on malicious links.