First published: Fri Oct 10 2014(Updated: )
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bmc Track-it\! | =11.3.0.355 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4874 has a severity rating of Medium, indicating a moderate risk to the affected system.
To fix CVE-2014-4874, upgrade to a version of BMC Track-It! that is not vulnerable, as specified by the vendor.
CVE-2014-4874 affects users of BMC Track-It! version 11.3.0.355.
CVE-2014-4874 is a local file inclusion vulnerability that allows unauthorized file access.
Yes, CVE-2014-4874 can potentially lead to other vulnerabilities or unauthorized access due to arbitrary file reading.