CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a ..
Does this matter?
Lower severity and a low EPSS score (4.93%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2) Filename or (3) SE_FNAME parameter to PlcmRmWeb/FileUpload or to read and remove arbitrary files via the (4) filePathName parameter in an importSipUriReservations SOAP request to PlcmRmWeb/JUserManager.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 4.93% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- polycom/realpresence resource manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdfVendor Advisory
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdfVendor Advisory
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.