CVE-2016-2349: High severity bmc remedy it service management suite vulnerability
Published Dec 21, 2016
·Updated
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
Affected Software
4 affected components
BMC Remedy Action Request System=8.1-sp2
BMC Remedy Action Request System=9.0
BMC Remedy Action Request System=9.0-sp1
BMC Remedy Action Request System=9.1
Event History
Dec 21, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2349?
CVE-2016-2349 is considered a critical vulnerability due to its potential to allow unauthorized password resets.
2
How do I fix CVE-2016-2349?
To fix CVE-2016-2349, apply the security patch provided by BMC for the affected versions of the Remedy AR System Server.
3
What versions are affected by CVE-2016-2349?
CVE-2016-2349 impacts BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1.
4
What is the impact of exploiting CVE-2016-2349?
Exploiting CVE-2016-2349 allows attackers to reset any user's password without knowing the previous password, leading to unauthorized access.
5
Is there a workaround for CVE-2016-2349?
Currently, the best approach to mitigate CVE-2016-2349 is to implement the official patches provided by BMC.