First published: Tue Jan 30 2018(Updated: )
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bmc Track-it\! | <=11.4 | |
Bmc Track-it\! | =11.4-hf1 | |
Bmc Track-it\! | =11.4-hf2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this BMC Track-It! vulnerability is CVE-2016-6598.
CVE-2016-6598 has a severity rating of 9.8 (Critical).
CVE-2016-6598 exposes an unauthenticated .NET remoting file storage service on port 9010, allowing file uploads to arbitrary paths on the affected machine running BMC Track-It!.
BMC Track-It! 11.4 before Hotfix 3, 11.4-hf1, and 11.4-hf2 are affected by CVE-2016-6598.
To mitigate the CVE-2016-6598 vulnerability, it is recommended to apply Hotfix 3 or upgrade to a newer version of BMC Track-It!.