Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Bmc Subscribe
Filtered by product Remedy Action Request System Server
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19505 1 Bmc 1 Remedy Action Request System Server 2019-02-15 4.0 MEDIUM 6.5 MEDIUM
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.