CVE-2015-4682: Infoleak
Published Sep 19, 2017
·Updated
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.
Affected Software
1 affected component
Polycom RealPresence Resource Manager<=8.3.2
Event History
Sep 19, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4682?
CVE-2015-4682 is classified as a medium severity vulnerability.
2
How can remote authenticated users exploit CVE-2015-4682?
Remote authenticated users can exploit CVE-2015-4682 by sending an HTTP POST request to extract the installation path.
3
What versions of the Polycom RealPresence Resource Manager are affected by CVE-2015-4682?
CVE-2015-4682 affects Polycom RealPresence Resource Manager versions prior to 8.4.
4
Is there a patch available for CVE-2015-4682?
Yes, upgrading to Polycom RealPresence Resource Manager version 8.4 or later mitigates CVE-2015-4682.
5
What type of vulnerability is CVE-2015-4682?
CVE-2015-4682 is a disclosure vulnerability that allows access to sensitive installation path information.