Back
CVE-2017-12815
CRITICAL
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.
Published: Mar 26, 2018
Modified: Jun 17, 2026
CWE-22
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| bomgar | remote_support | - |
GitHub Security Advisory GHSA-vx88-5hj8-432c
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that...
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
1.99%
Top 21% most likely to be exploited
Threat Score
40.6 / 100
Data Sources
NVD
EPSS
GitHub