CVE-2019-11216: Malicious File Upload
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11216?
CVE-2019-11216 is a vulnerability in BMC Smart Reporting 7.3 20180418 that allows authenticated XXE attacks within the import functionality.
What is the severity of CVE-2019-11216?
The severity of CVE-2019-11216 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2019-11216?
The affected software versions include Bmc Remedy Smart Reporting 9.1.03.001 to 9.1.03, 9.1.04.002 to 9.1.04, 18.05.05 to 18.05, and 19.02.01 to 19.02.
What can an attacker do with CVE-2019-11216?
An attacker can perform XXE attacks to download local files from the server or launch DoS attacks with XML expansion attacks.
How can I mitigate the vulnerability in CVE-2019-11216?
To mitigate the vulnerability, it is recommended to upgrade to a fixed version of BMC Smart Reporting.