4
CVSSv2

CVE-2018-19505

Published: 03/01/2019 Updated: 15/02/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bmc remedy action request system server 7.1

Exploits

An impersonation issue in BMC Remedy version 71 may lead to incorrect user context in Remedy AR System Server ...