PT-2019-14814 · Bmc · Bmc Remedy Itsm Suite Smartit+1
Published
2019-09-26
·
Updated
2019-10-02
·
CVE-2019-16755
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BMC Remedy ITSM Suite DWP versions 3.x through 18.x
BMC Remedy ITSM Suite SmartIT versions 1.x through 19.02
Description
The issue allows remote attackers to execute remote commands on the operating system running the targeted application without prior authentication. This is due to unspecified vulnerabilities in both DWP and SmartIT components.
Recommendations
For DWP versions 3.x through 18.x, update to a version that includes a fix for this issue.
For SmartIT versions 1.x through 19.02, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the DWP and SmartIT components to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Remedy Itsm Suite Dwp
Bmc Remedy Itsm Suite Smartit