Vulnerability Description
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bmc | Remedy Action Request System | 8.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95075
- http://www.securitytracker.com/id/1037529
- https://bmcsites.force.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA214000000l6kbCAMitigationVendor Advisory
- http://www.securityfocus.com/bid/95075
- http://www.securitytracker.com/id/1037529
- https://bmcsites.force.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA214000000l6kbCAMitigationVendor Advisory
FAQ
What is CVE-2016-2349?
CVE-2016-2349 is a vulnerability with a CVSS score of 7.5 (HIGH). Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
How severe is CVE-2016-2349?
CVE-2016-2349 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2349?
Check the references section above for vendor advisories and patch information. Affected products include: Bmc Remedy Action Request System.