CVE-2015-4684
Last modified
CVE-2015-4684 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2) Filename or (3) SE_FNAME parameter to PlcmRmWeb/FileUpload or to read and remove arbitrary files via the (4) filePathName parameter in an importSipUriReservations SOAP request to PlcmRmWeb/JUserManager.. EPSS estimates a 4.93% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2) Filename or (3) SE_FNAME parameter to PlcmRmWeb/FileUpload or to read and remove arbitrary files via the (4) filePathName parameter in an importSipUriReservations SOAP request to PlcmRmWeb/JUserManager.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Polycom | Realpresence Resource Manager | <= 8.3.2 |
References
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/75432Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37449/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4684?
How severe is CVE-2015-4684?
How do I fix CVE-2015-4684?
Are you affected by CVE-2015-4684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
