Unrated severityNVD Advisory· Published Jan 3, 2019· Updated Aug 5, 2024
CVE-2018-19505
CVE-2018-19505
Description
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: = 7.1
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/150492/BMC-Remedy-7.1-User-Impersonation.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2018/Nov/62mitremailing-listx_refsource_FULLDISC
- www.securitytracker.com/id/1042177mitrevdb-entryx_refsource_SECTRACK
News mentions
0No linked articles in our index yet.