EXPOSURES › CVE-2017-17674
CVE-2017-17674
CRITICAL
DETAIL
SourceNVD · cve
Published2021-05-19
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-17674 ↗
⚡ RCE
SHAME 50/100
rce
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
Damning vulnerability disclosure with no vendor response
Critical RCE vulnerability disclosed
"BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE)."
Neutral database listing
Neutral database listing
Neutral database listing
Neutral database listing
Neutral database listing
Neutral database listing
AFFECTED FEDRAMP PRODUCTS · 1
| PRODUCT | STATUS |
|---|---|
| BMC Helix BMC Software |
Authorized |