CVE-2019-16755: Bmc Myit Digital Workplace

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.

Affected products

  • Bmc Myit Digital Workplace: before 18.08.00 (fixed in 18.08.00)

Published 2019-09-26. Last modified 2026-06-17.