ZeroHour

CVE-2019-11216

PoC ×2
CVSS 3.1
6.5 medium
EPSS
2%p78
Published
()
Modified
Description

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

Vendors
bmc
Products
remedy smart reporting
Weakness
CWE-434, CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.