PT-2020-7853 · Bmc · Bmc Remedy Ar System Server
Published
2020-01-15
·
Updated
2020-01-24
·
CVE-2015-5072
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
BMC Remedy AR System Server versions prior to 9.0 SP1
Description:
The issue allows remote authenticated users to access arbitrary local files. This is achieved by manipulating the
imageid parameter in the BIRT Engine servlet, part of the AR System Mid Tier component.Recommendations:
For versions prior to 9.0 SP1, update to version 9.0 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the BIRT Engine servlet to minimize the risk of exploitation. Avoid using the
imageid parameter in the affected servlet until the issue is resolved.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Remedy Ar System Server