CVE-2015-4683

CRITICAL

Polycom Realpresence Resource Manager < 8.3.2 - Access Control

Title source: rule

Description

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.

Exploits (1)

exploitdb WRITEUP
by SEC Consult · textwebappshardware
https://www.exploit-db.com/exploits/37449

Scores

CVSS v3 9.8
EPSS 0.3431
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-264
Status draft

Affected Products (1)

polycom/realpresence_resource_manager < 8.3.2

Timeline

Published Sep 19, 2017
Tracked Since Feb 18, 2026