CVE-2017-12815: Path Traversal
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12815?
CVE-2017-12815 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2017-12815?
To fix CVE-2017-12815, update to a patched version of the Bomgar Remote Support Portal that addresses the path traversal issue.
What systems are affected by CVE-2017-12815?
CVE-2017-12815 affects versions of the Bomgar Remote Support Portal prior to version 52790.
What type of vulnerability is CVE-2017-12815?
CVE-2017-12815 is a path traversal vulnerability that can be exploited to access restricted files.
Can CVE-2017-12815 lead to data exposure?
Yes, CVE-2017-12815 can potentially lead to unauthorized access and exposure of sensitive data.