CVE-2016-6598
BMC Track-It! 11.4 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.
BMC Track-It! en versiones 11.4 anteriores a Hotfix 3 expone un servicio de almacenamiento de archivos en remoto .NET no autenticado (FileStorageService) en el puerto 9010. Este servicio contiene un método que permite la subida de un archivo a una ruta arbitraria en la máquina que ejecuta Track-It!. Esto puede ser empleado para subir un archivo en el root web y lograr la ejecución de código como NETWORK SERVICE o SYSTEM.
BMC Track-It! version 11.4 suffers from remote code execution and credential disclosure vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-28 First Exploit
- 2016-08-04 CVE Reserved
- 2018-01-26 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bmc Search vendor "Bmc" | Track-it\! Search vendor "Bmc" for product "Track-it\!" | <= 11.4 Search vendor "Bmc" for product "Track-it\!" and version " <= 11.4" | - |
Affected
| ||||||
Bmc Search vendor "Bmc" | Track-it\! Search vendor "Bmc" for product "Track-it\!" | 11.4 Search vendor "Bmc" for product "Track-it\!" and version "11.4" | hf1 |
Affected
| ||||||
Bmc Search vendor "Bmc" | Track-it\! Search vendor "Bmc" for product "Track-it\!" | 11.4 Search vendor "Bmc" for product "Track-it\!" and version "11.4" | hf2 |
Affected
|