CVE-2016-6598: Bmc Track-It!

Critical severity, CVSS 9.8. EPSS: 19.2% chance of exploitation in the next 30 days.

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.

Affected products

  • Bmc Track-It!: up to and including 11.4; version 11.4 only

Published 2018-01-30. Last modified 2026-06-17.