CVE-2014-4874: Infoleak
Published Oct 10, 2014
·Updated
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
Affected Software
1 affected component
BMC Track-it\!=11.3.0.355
Event History
Oct 10, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4874?
CVE-2014-4874 has a severity rating of Medium, indicating a moderate risk to the affected system.
2
How do I fix CVE-2014-4874?
To fix CVE-2014-4874, upgrade to a version of BMC Track-It! that is not vulnerable, as specified by the vendor.
3
Who is affected by CVE-2014-4874?
CVE-2014-4874 affects users of BMC Track-It! version 11.3.0.355.
4
What type of vulnerability is CVE-2014-4874?
CVE-2014-4874 is a local file inclusion vulnerability that allows unauthorized file access.
5
Can CVE-2014-4874 lead to further exploitation?
Yes, CVE-2014-4874 can potentially lead to other vulnerabilities or unauthorized access due to arbitrary file reading.