BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.
References
Link | Resource |
---|---|
http://bmc.com | Product |
https://docs.bmc.com/docs/ars91/en/9-1-00-fixes-available-for-remedy-ar-system-security-vulnerabilities-800555806.html | Release Notes Vendor Advisory |
https://seclists.org/fulldisclosure/2017/Oct/52 | Mailing List Third Party Advisory |
http://remedy.com | Product |
Configurations
Information
Published : 2021-05-19 07:15
Updated : 2021-05-25 11:20
NVD link : CVE-2017-17675
Mitre link : CVE-2017-17675
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
bmc
- remedy_mid-tier