PT-2021-8567 · Bmc · Bmc Remedy Mid Tier

Kristian Varnai

+1

·

Published

2021-05-19

·

Updated

2021-05-25

·

CVE-2017-17674

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BMC Remedy Mid Tier version 9.1SP3
Description The system is affected by remote and local file inclusion due to a lack of restrictions on targeted files. This can lead to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).
Recommendations For BMC Remedy Mid Tier version 9.1SP3, consider restricting access to sensitive files and directories to minimize the risk of exploitation. As a temporary workaround, limit the ability to include remote and local files until a patch is available.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17674

Affected Products

Bmc Remedy Mid Tier