Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Bmc Subscribe
Filtered by product Remedy It Service Management Suite
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26088 1 Bmc 1 Remedy It Service Management Suite 2022-11-15 N/A 5.4 MEDIUM
An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."