PT-2019-14814 · Bmc · Bmc Remedy Itsm Suite Smartit+1
Publicado
2019-09-26
·
Atualizado
2019-10-02
·
CVE-2019-16755
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BMC Remedy ITSM Suite DWP versions 3.x through 18.x
BMC Remedy ITSM Suite SmartIT versions 1.x through 19.02
Description
The issue allows remote attackers to execute remote commands on the operating system running the targeted application without prior authentication. This is due to unspecified vulnerabilities in both DWP and SmartIT components.
Recommendations
For DWP versions 3.x through 18.x, update to a version that includes a fix for this issue.
For SmartIT versions 1.x through 19.02, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the DWP and SmartIT components to minimize the risk of exploitation.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bmc Remedy Itsm Suite Dwp
Bmc Remedy Itsm Suite Smartit