First published: Wed May 19 2021(Updated: )
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Remedy Mid-Tier | =9.1-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17677 is a vulnerability affecting BMC Remedy 9.1SP3 that allows authenticated users with report creation rights to execute arbitrary code using BIRT templates.
CVE-2017-17677 has a severity rating of 8.8 (high).
To fix CVE-2017-17677, it is recommended to apply the available fixes provided by BMC and update to the latest version of BMC Remedy.
More information about CVE-2017-17677 can be found in the references provided: http://bmc.com, http://remedy.com, and the official documentation from BMC.
The CWE-ID of CVE-2017-17677 is 732.