CVE-2018-19505: Bmc Remedy Action Request System Server
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.
Affected products
- Bmc Remedy Action Request System Server: version 7.1 only
Published 2019-01-03. Last modified 2026-06-17.