Описание
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 8.3.2 (включая)
cpe:2.3:a:polycom:realpresence_resource_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.34308
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
EPSS
Процентиль: 97%
0.34308
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-264