CVE-2016-6598: Critical severity bmc track-it! vulnerability
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this BMC Track-It! vulnerability?
The vulnerability ID for this BMC Track-It! vulnerability is CVE-2016-6598.
What is the severity rating of CVE-2016-6598?
CVE-2016-6598 has a severity rating of 9.8 (Critical).
How does CVE-2016-6598 affect BMC Track-It!?
CVE-2016-6598 exposes an unauthenticated .NET remoting file storage service on port 9010, allowing file uploads to arbitrary paths on the affected machine running BMC Track-It!.
Which versions of BMC Track-It! are affected by CVE-2016-6598?
BMC Track-It! 11.4 before Hotfix 3, 11.4-hf1, and 11.4-hf2 are affected by CVE-2016-6598.
How can I mitigate the CVE-2016-6598 vulnerability?
To mitigate the CVE-2016-6598 vulnerability, it is recommended to apply Hotfix 3 or upgrade to a newer version of BMC Track-It!.