SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11216

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality.

MEDIUM 6.5EPSS 1.84%

Does this matter?

Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.

Description

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
EPSS
1.84% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-434, CWE-611
Affected
bmc/remedy smart reporting
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.