← Back

CVE-2019-11216

nvd nist
Published: Dec 4, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

Affected (4)

1 product
Remedy Smart Reporting
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Bmc
From 18.05 to 18.05.05
From 19.02 to 19.02.01
From 9.1.03 to 9.1.03.001
From 9.1.04 to 9.1.04.002

References (6)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.