PT-2015-3359 · Bmc · Bmc Track-It!
Pedro Ribeiro
·
Published
2015-12-24
·
Updated
2018-02-26
·
CVE-2016-6598
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BMC Track-It! versions prior to 11.4 Hotfix 3
Description
The issue is related to insufficient access control in the FileStorageService, which exposes an unauthenticated .NET remoting file storage service on port 9010. This allows an attacker to upload a file to an arbitrary path on the machine, potentially leading to code execution as NETWORK SERVICE or SYSTEM. The vulnerability can be exploited by a remote attacker to upload files to the web root, achieving code execution with elevated privileges.
Recommendations
For versions prior to 11.4 Hotfix 3, apply Hotfix 3 to resolve the issue. As a temporary workaround, consider restricting access to the FileStorageService on port 9010 to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Track-It!