Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12815

Опубликовано: 26 мар. 2018
Источник: nvd
CVSS3: 10
CVSS2: 10
EPSS Низкий

Описание

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using and/or tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bomgar:remote_support:-:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00493
Низкий

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 10
github
больше 3 лет назад

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

CVSS3: 10
fstec
больше 8 лет назад

Уязвимость компонента JavaStart.jar веб-портала информационно-технической поддержки Bomgar Remote Support Portal, позволяющая нарушителю создавать, изменять или удалять произвольные файлы

EPSS

Процентиль: 65%
0.00493
Низкий

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-22