Skip to content
COOEY

EXPOSURES › CVE-2017-17674

CVE-2017-17674

CRITICAL
DETAIL
SourceNVD · cve Published2021-05-19 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-17674 ↗
⚡ RCE SHAME 50/100 rce

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Damning vulnerability disclosure with no vendor response
cooey ↗ severe-fallout -0.90
Critical RCE vulnerability disclosed
"BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE)."
app.opencve.io ↗ severe-fallout +0.00
Neutral database listing
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
NVD ↗ severe-fallout +0.00
Neutral database listing
CISA ↗ severe-fallout +0.00
Neutral database listing
cybersecuritynews.com ↗ severe-fallout +0.00
Neutral database listing
www.claimdepot.com ↗ severe-fallout +0.00
Neutral database listing
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
BMC Helix
BMC Software
Authorized