CVE-2016-2349: Bmc Remedy Action Request System
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
Affected products
- Bmc Remedy Action Request System: version 8.1 only; version 9.0 only; version 9.1 only
Published 2016-12-21. Last modified 2026-06-17.