Description
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database name, username and password as well as the domain administrator username and password. These are encrypted with a fixed key and IV ("NumaraIT") using the DES algorithm. The domain administrator username and password can only be obtained if the Self-Service component is enabled, which is the most common scenario in enterprise deployments.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:36:28.607Z
Reserved: 2016-08-04T00:00:00.000Z
Link: CVE-2016-6599
No data.
Status : Modified
Published: 2018-01-30T20:29:00.397
Modified: 2024-11-21T02:56:24.697
Link: CVE-2016-6599
No data.
OpenCVE Enrichment
No data.
Weaknesses