Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BMC Remedy Remedy AR System Server 安全漏洞
Vulnerability Description
BMC Remedy是美国BMC Software公司的一套用于IT部门的移动数字化企业管理平台。Remedy AR System Server是其中的一个服务器端。 BMC Remedy 7.1版本中的Remedy AR System Server存在安全漏洞,该漏洞源于程序没有在模拟的情景中设置正确的用户上下文。攻击者可利用该漏洞以其他用户身份进行操作。
CVSS Information
N/A
Vulnerability Type
N/A