VulnerabilityModified
CVE-2015-4682
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.
MEDIUM 6.5EPSS 5.23%
Does this matter?
Lower severity and a low EPSS score (5.23%). Track it; it rarely justifies an emergency change on its own.
Description
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.23% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- polycom/realpresence resource manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdfVendor Advisory
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdfVendor Advisory
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.