PT-2019-9839 · Bmc · Bmc Remedy

Rafael Pedrero

·

Publicado

2019-01-03

·

Atualizado

2019-02-15

·

CVE-2018-19505

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BMC Remedy versions 7.1
Description The issue arises from the Remedy AR System Server in BMC Remedy, where it may fail to set the correct user context in certain impersonation scenarios. This can allow a user to act with the identity of a different user. The problem is specifically related to the userdata.js in the WOI:WorkOrderConsole component, which allows a username substitution involving a UserData Init call.
Recommendations For version 7.1, consider restricting access to the WOI:WorkOrderConsole component until a fix is available, and avoid using the UserData Init call in scenarios where user impersonation is involved.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19505

Produtos afetados

Bmc Remedy