Vulnerability Description
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Polycom | Realpresence Resource Manager | <= 8.3.2 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-ManageExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party AdvisoryVDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_CentVendor Advisory
- https://www.exploit-db.com/exploits/37449/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-ManageExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Jun/81ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432Third Party AdvisoryVDB Entry
- https://support.polycom.com/global/documents/support/documentation/Security_CentVendor Advisory
- https://www.exploit-db.com/exploits/37449/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2015-4683?
CVE-2015-4683 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with...
How severe is CVE-2015-4683?
CVE-2015-4683 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-4683?
Check the references section above for vendor advisories and patch information. Affected products include: Polycom Realpresence Resource Manager.