PT-2014-8443 · Bmc · Bmc Track-It!
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
BMC Track-It! version 11.3
Description
The issue allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset. This is related to a credential information disclosure vulnerability in the web account component.
Recommendations
For version 11.3, consider restricting access to the password reset functionality until a fix is available, and avoid creating accounts with names that match local system accounts to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bmc Track-It!