CVE-2019-16755 Information

Description

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x all versions service packs and patches are affected by this vulnerability. Affected SmartIT versions: 1.x 2.0 18.05 18.08 and 19.02 all versions service packs and patches are affected by this vulnerability.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://bmcsites.force.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA21O000000gnYQSAY&type=Solution

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: