Medium severity6.5NVD Advisory· Published Jan 3, 2019· Updated Jun 17, 2026
CVE-2018-19505
CVE-2018-19505
Description
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 7.1
- cpe:2.3:a:bmc:remedy_action_request_system_server:7.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/150492/BMC-Remedy-7.1-User-Impersonation.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Nov/62nvdMailing ListThird Party Advisory
- www.securitytracker.com/id/1042177nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.