First published: Mon Mar 26 2018(Updated: )
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Remote Support |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12815 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2017-12815, update to a patched version of the Bomgar Remote Support Portal that addresses the path traversal issue.
CVE-2017-12815 affects versions of the Bomgar Remote Support Portal prior to version 52790.
CVE-2017-12815 is a path traversal vulnerability that can be exploited to access restricted files.
Yes, CVE-2017-12815 can potentially lead to unauthorized access and exposure of sensitive data.