PT-2022-16432 · Bmc · Bmc Track-It!

Markus Wulftange

+1

·

Published

2022-02-10

·

Updated

2022-03-01

·

CVE-2022-24047

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BMC Track-It! version 20.21.01.102
Description This issue allows remote attackers to bypass authentication on affected installations. The flaw exists within the authorization of HTTP requests due to the lack of authentication prior to allowing access to functionality. An attacker can leverage this to bypass authentication on the system.
Recommendations For version 20.21.01.102, consider restricting access to the HTTP module to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and strengthen the authorization of HTTP requests to ensure proper authentication is required before allowing access to functionality.

Fix

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24047
ZDI-22-290

Affected Products

Bmc Track-It!