CVE-2017-18223: Bmc Remedy Action Request System

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.

Affected products

  • Bmc Remedy Action Request System: before 9.1.03 (fixed in 9.1.03)

Published 2018-03-10. Last modified 2026-06-17.