6.5
CVSSv3

CVE-2019-11216

Published: 04/12/2019 Updated: 13/12/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bmc remedy smart reporting

Exploits

BMC Smart Reporting version 73 20180418 suffers from an XML external entity injection vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> XXE in BMC Smart Reporting 73 20180418 - CVE-2019-11216 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: ...