PT-2018-4965 · Bmc · Bmc Track-It!

Pedro Ribeiro

·

Published

2018-01-30

·

Updated

2018-02-26

·

CVE-2016-6599

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BMC Track-It! versions prior to 11.4 Hotfix 3
Description The issue exposes an unauthenticated .NET remoting configuration service on port 9010, specifically the ConfigurationService. This service has a method that can be used to retrieve a configuration file containing sensitive information such as the application database name, username, password, and the domain administrator username and password. The sensitive information is encrypted using the DES algorithm with a fixed key and IV ("NumaraIT"). The domain administrator credentials can be obtained if the Self-Service component is enabled, a common setup in enterprise environments.
Recommendations For versions prior to 11.4 Hotfix 3, apply Hotfix 3 to resolve the issue. As a temporary workaround, consider disabling the ConfigurationService on port 9010 until the hotfix is applied. Restrict access to the ConfigurationService to minimize the risk of exploitation. Avoid using the fixed key and IV ("NumaraIT") for encryption until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6599

Affected Products

Bmc Track-It!