PT-2020-7852 · Bmc · Bmc Remedy Ar System Server
Published
2020-01-15
·
Updated
2020-01-24
·
CVE-2015-5071
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
BMC Remedy AR System Server versions prior to 9.0 SP1
Description:
The issue allows remote authenticated users to access arbitrary files by manipulating the
report parameter of the BIRT viewer servlet in the AR System Mid Tier component.Recommendations:
For versions prior to 9.0 SP1, update to version 9.0 SP1 or later to resolve the issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Remedy Ar System Server