// For flags

CVE-2017-12815

Bomgar Remote Support Portal (RSP) Path Traversal

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

El análisis del Applet 52790 y anteriores de JavaStart.jar en Bomgar Remote Support Portal reveló que es susceptible a una vulnerabilidad de salto de directorio. Este archivo se puede descargar desde una determinada implementación de Bomgar Remote Support Portal en https://domain/api/content/JavaStart.jar y se puede invocar desde un sitio web arbitrario mediante las etiquetas <object> y/o . Una explotación exitosa resulta en la creación, modificación o eliminación de archivos en el sistema operativo y con los privilegios del usuario que ejecutó el applet de Java.

Bomgar Remote Support Portal (RSP) suffers from a path traversal vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-08-11 CVE Reserved
  • 2018-03-23 CVE Published
  • 2018-03-23 First Exploit
  • 2024-08-05 CVE Updated
  • 2024-12-06 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bomgar
Search vendor "Bomgar"
Remote Support
Search vendor "Bomgar" for product "Remote Support"
--
Affected