This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Track-It! |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-16690 is considered to be moderate, due to the requirement of authentication to exploit the vulnerability.
To fix ZDI-CAN-16690, you should update to the latest version of BMC Track-It! that addresses this vulnerability.
Exploiting ZDI-CAN-16690 can lead to the disclosure of sensitive information from affected BMC Track-It! installations.
Yes, ZDI-CAN-16690 requires authentication to exploit, meaning an attacker must have valid credentials.
ZDI-CAN-16690 affects installations of BMC Track-It!.