BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote malicious users to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bmc track-it\\! 11.3.0.355 |