CVE-2014-4872: High severity bmc track-it! vulnerability
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4872?
CVE-2014-4872 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-4872?
To remediate CVE-2014-4872, ensure that TCP port 9010 requires authentication and restrict access to authorized users only.
What are the impacts of CVE-2014-4872 on BMC Track-It!?
CVE-2014-4872 can allow attackers to upload arbitrary files, execute code, and access sensitive information without authentication.
Which version of BMC Track-It! is affected by CVE-2014-4872?
CVE-2014-4872 specifically affects BMC Track-It! version 11.3.0.355.
Can attackers exploit CVE-2014-4872 remotely?
Yes, attackers can exploit CVE-2014-4872 remotely due to the lack of authentication on the specified TCP port.