CVE-2015-5072
Summary
| CVE | CVE-2015-5072 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-15 18:15:00 UTC |
| Updated | 2020-01-24 18:27:00 UTC |
| Description | The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bmc | Remedy Ar System Server | 8.0 | All | All | All |
| Application | Bmc | Remedy Ar System Server | 9.0 | All | All | All |
| Application | Bmc | Remedy Ar System Server | 8.0 | All | All | All |
| Application | Bmc | Remedy Ar System Server | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Resolving BIRT Security Issues ISS04485990 (CVE... | BMC Communities | CONFIRM | communities.bmc.com | Vendor Advisory |
| BMC Remedy AR 8.1 / 9.0 File Inclusion ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.