First published: Wed Dec 21 2016(Updated: )
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Remedy Action Request System | =8.1-sp2 | |
BMC Remedy Action Request System | =9.0 | |
BMC Remedy Action Request System | =9.0-sp1 | |
BMC Remedy Action Request System | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2349 is considered a critical vulnerability due to its potential to allow unauthorized password resets.
To fix CVE-2016-2349, apply the security patch provided by BMC for the affected versions of the Remedy AR System Server.
CVE-2016-2349 impacts BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1.
Exploiting CVE-2016-2349 allows attackers to reset any user's password without knowing the previous password, leading to unauthorized access.
Currently, the best approach to mitigate CVE-2016-2349 is to implement the official patches provided by BMC.