BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset.
References
Configurations
Information
Published : 2014-12-12 03:59
Updated : 2014-12-12 12:38
NVD link : CVE-2014-8270
Mitre link : CVE-2014-8270
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
bmc
- bmc_track-it\!