Intrusion Prevention

BMC.Track-It.FileStorageService.Arbitrary.File.Upload

Description

This indicates an attack attempt to exploit a file upload vulnerability in Numara / BMC Track-It!.
The vulnerability is due to an design flaw when the vulnerable module handles an unauthenticated file upload request. A remote attacker could exploit this to execute arbitrary code within the context of target application.

Affected Products

Numara / BMC Track-It! versions 11.3.0.355 and prior

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

CVE References

CVE-2014-4872