Medium severity6.5NVD Advisory· Published Dec 4, 2019· Updated Jun 17, 2026
CVE-2019-11216
CVE-2019-11216
Description
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.
Affected products
3- cpe:2.3:a:bmc:remedy_smart_reporting:*:*:*:*:*:*:*:*Range: >=9.1.03,<=9.1.03.001
- BMC/Smart Reportingdescription
- Range: 7.3 20180418
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/155552/BMC-Smart-Reporting-7.3-20180418-XML-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Dec/7nvdExploitMailing ListThird Party Advisory
- docs.bmc.com/docs/itsm90/export-and-import-repository-509983929.htmlnvdProduct
News mentions
0No linked articles in our index yet.