vendor:
Remedy Knowledge Management
by:
Unknown
7.5
CVSS
HIGH
Default Account, Cross-Site Scripting (XSS)
798, 79
CWE
Product Name: Remedy Knowledge Management
Affected Version From: Remedy Knowledge Management 7.5.00
Affected Version To: Unknown
Patch Exists: No
Related CWE:
CPE: a:bmc:remedy_knowledge_management:7.5.00
Platforms Tested:
Unknown
BMC Remedy Knowledge Management Default Account and XSS Vulnerabilities
The default-account vulnerability allows attackers to bypass authentication and gain unauthorized access. The cross-site scripting vulnerabilities enable attackers to execute arbitrary script code in the browser of unsuspecting users, potentially leading to theft of authentication credentials and other attacks.
Mitigation:
Apply the latest security patches provided by BMC. Limit access to the affected application to trusted networks or users. Regularly monitor and review logs for any suspicious activity.