CVE-2017-3890: Blackberry Appliance-X

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.

Affected products

  • Blackberry Appliance-X: up to and including 1.8.1
  • Blackberry Workspaces Vapp: version 4.6.0 only; version 5.4.1 only

Published 2017-01-13. Last modified 2026-06-17.